2.1
CVSSv2

CVE-2000-0679

Published: 20/10/2000 Updated: 05/09/2008
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary files.

Vulnerable Product Search on Vulmon Subscribe to Product

cvs cvs 1.10.8

Exploits

source: wwwsecurityfocuscom/bid/1523/info The cvs client blindly trust paths returned to it by the server Therefore, a cvs client could be tricked into creating a file anywhere on the system by a malicious server This problem can be tested yourself as follows Although this example runs a faked cvs server using the :ext: method, this ...