CVE Vulnerabilities

CVE-2005-4830

Published: Dec 31, 2005 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.6 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

CRLF injection vulnerability in viewcvs in ViewCVS 0.9.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the content-type parameter.

Affected Software

Name Vendor Start Version End Version
Viewcvs Viewcvs 0.9.2 (including) 0.9.2 (including)
Viewcvs Ubuntu dapper *
Viewcvs Ubuntu edgy *
Viewcvs Ubuntu feisty *
Viewvc Ubuntu devel *
Viewvc Ubuntu gutsy *
Viewvc Ubuntu hardy *
Viewvc Ubuntu intrepid *
Viewvc Ubuntu jaunty *
Viewvc Ubuntu karmic *
Viewvc Ubuntu upstream *

References