|
|
Subscribe / Log in / New account

cvs: code execution

Package(s):cvs CVE #(s):CVE-2010-3846
Created:October 29, 2010 Updated:November 30, 2010
Description: From the Red Hat bugzilla:

An array index error, leading to heap-based buffer overflow was found in the way CVS version control system applied certain delta fragments changes from input file in the RCS (Revision Control System file) format. A local attacker could store a specially-crafted RCS file into the CVS repository and trick the remote victim to checkout (update their CVS repository tree) with this file, which could lead to arbitrary code execution with the privileges of the user running cvs client executable.

Alerts:
Red Hat RHSA-2010:0918-01 cvs 2010-11-29
Fedora FEDORA-2010-16721 cvs 2010-10-28
Fedora FEDORA-2010-16599 cvs 2010-10-22
Fedora FEDORA-2010-16600 cvs 2010-10-22

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds