[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2012:044 -- Mandriva cvs

ID: oval:org.secpod.oval:def:302817Date: (C)2012-12-11   (M)2023-07-28
Class: PATCHFamily: unix




A vulnerability has been found and corrected in cvs: A heap-based buffer overflow flaw was found in the way the CVS client handled responses from HTTP proxies. A malicious HTTP proxy could use this flaw to cause the CVS client to crash or, possibly, execute arbitrary code with the privileges of the user running the CVS client . The updated packages have been patched to correct this issue.

Platform:
Mandriva Linux 2011.0
Mandriva Linux 2010.1
Product:
cvs
Reference:
MDVSA-2012:044
CVE-2012-0804
CVE    1
CVE-2012-0804
CPE    2
cpe:/o:mandriva:linux:2010.1
cpe:/o:mandriva:linux:2011.0

© SecPod Technologies