Lucene search

K
cve[email protected]CVE-2004-0180
HistoryJun 01, 2004 - 4:00 a.m.

CVE-2004-0180

2004-06-0104:00:00
web.nvd.nist.gov
31
cvs
remote code execution
vulnerability
arbitrary file creation
security
nvd

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

6.4 Medium

AI Score

Confidence

Low

0.011 Low

EPSS

Percentile

84.5%

The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.

Affected configurations

NVD
Node
cvscvsRange1.10
CPENameOperatorVersion
cvs:cvscvsle1.10

References

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

6.4 Medium

AI Score

Confidence

Low

0.011 Low

EPSS

Percentile

84.5%