5
CVSSv2

CVE-2004-0405

Published: 01/06/2004 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

CVS prior to 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cvs cvs

Vendor Advisories

Two vulnerabilities have been discovered and fixed in CVS: CAN-2004-0180 Sebastian Krahmer discovered a vulnerability whereby a malicious CVS pserver could create arbitrary files on the client system during an update or checkout operation, by supplying absolute pathnames in RCS diffs CAN-2004-0405 Derek Robert Price discovered a vulnerabilit ...