CVE Vulnerabilities

CVE-2004-0418

Published: Aug 06, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an out-of-bounds write for a single byte to execute arbitrary code or modify critical program data.

Affected Software

NameVendorStart VersionEnd Version
CvsCvs1.10.7 (including)1.10.7 (including)
CvsCvs1.10.8 (including)1.10.8 (including)
CvsCvs1.11 (including)1.11 (including)
CvsCvs1.11.1 (including)1.11.1 (including)
CvsCvs1.11.1_p1 (including)1.11.1_p1 (including)
CvsCvs1.11.2 (including)1.11.2 (including)
CvsCvs1.11.3 (including)1.11.3 (including)
CvsCvs1.11.4 (including)1.11.4 (including)
CvsCvs1.11.5 (including)1.11.5 (including)
CvsCvs1.11.6 (including)1.11.6 (including)
CvsCvs1.11.10 (including)1.11.10 (including)
CvsCvs1.11.11 (including)1.11.11 (including)
CvsCvs1.11.14 (including)1.11.14 (including)
CvsCvs1.11.15 (including)1.11.15 (including)
CvsCvs1.11.16 (including)1.11.16 (including)
CvsCvs1.12.1 (including)1.12.1 (including)
CvsCvs1.12.2 (including)1.12.2 (including)
CvsCvs1.12.5 (including)1.12.5 (including)
CvsCvs1.12.7 (including)1.12.7 (including)
CvsCvs1.12.8 (including)1.12.8 (including)
OpenpkgOpenpkg**
OpenpkgOpenpkg1.3 (including)1.3 (including)
OpenpkgOpenpkg2.0 (including)2.0 (including)
PropackSgi2.4 (including)2.4 (including)
PropackSgi3.0 (including)3.0 (including)
Red Hat Enterprise Linux 3RedHatcvs-0:1.11.2-24*
CvsUbuntudapper*
CvsUbuntudevel*
CvsUbuntuedgy*
CvsUbuntufeisty*

References