CVE-2004-0414
cvs - buffer overflow
EPSS 4.0%
描述
CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.
如何修補 CVE-2004-0414
要修補 CVE-2004-0414,請將受影響套件升級到下列已修補版本。
- Debian/cvs—升級至 1:1.12.9-1 或更新版本
- Debian/cvs—升級至 1.11.1p1debian-9woody6 或更新版本
CVE-2004-0414 正在被利用嗎?
低 — EPSS 為 4.0%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 1:1.12.9-1
- from 0, < 1.11.1p1debian-9woody6