CVE Vulnerabilities

CVE-2004-0180

Published: Jun 01, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.

Affected Software

NameVendorStart VersionEnd Version
CvsCvs*1.10 (including)
Red Hat Enterprise Linux 3RedHatcvs-0:1.11.2-18*
Red Hat Linux 9RedHat*
CvsUbuntudapper*
CvsUbuntudevel*
CvsUbuntuedgy*
CvsUbuntufeisty*

References