CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which causes different error messages to be returned.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cvs | Cvs | 1.10.6 | 1.10.6 |
Cvs | Cvs | 1.10.7 | 1.10.7 |
Cvs | Cvs | 1.10.8 | 1.10.8 |
Cvs | Cvs | 1.11 | 1.11 |
Cvs | Cvs | 1.11.1 | 1.11.1 |
Cvs | Cvs | 1.11.1_p1 | 1.11.1_p1 |
Cvs | Cvs | 1.11.2 | 1.11.2 |
Cvs | Cvs | 1.11.3 | 1.11.3 |
Cvs | Cvs | 1.11.4 | 1.11.4 |
Cvs | Cvs | 1.11.5 | 1.11.5 |
Cvs | Cvs | 1.11.6 | 1.11.6 |
Cvs | Cvs | 1.11.10 | 1.11.10 |
Cvs | Cvs | 1.11.11 | 1.11.11 |
Cvs | Cvs | 1.11.14 | 1.11.14 |
Cvs | Cvs | 1.11.15 | 1.11.15 |
Cvs | Cvs | 1.11.16 | 1.11.16 |
Cvs | Cvs | 1.12.1 | 1.12.1 |
Cvs | Cvs | 1.12.2 | 1.12.2 |
Cvs | Cvs | 1.12.5 | 1.12.5 |
Cvs | Cvs | 1.12.7 | 1.12.7 |
Cvs | Cvs | 1.12.8 | 1.12.8 |
Red Hat Enterprise Linux 3 | RedHat | cvs-0:1.11.2-24 | * |