Lucene search

K
cve[email protected]CVE-2004-0417
HistoryAug 06, 2004 - 4:00 a.m.

CVE-2004-0417

2004-08-0604:00:00
web.nvd.nist.gov
33
cve-2004-0417
integer overflow
max-dotdot
cvs protocol command
server crash
disk space
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.5 Medium

AI Score

Confidence

Low

0.931 High

EPSS

Percentile

99.1%

Integer overflow in the “Max-dotdot” CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.

Affected configurations

NVD
Node
cvscvsMatch1.10.7
OR
cvscvsMatch1.10.8
OR
cvscvsMatch1.11
OR
cvscvsMatch1.11.1
OR
cvscvsMatch1.11.1_p1
OR
cvscvsMatch1.11.2
OR
cvscvsMatch1.11.3
OR
cvscvsMatch1.11.4
OR
cvscvsMatch1.11.5
OR
cvscvsMatch1.11.6
OR
cvscvsMatch1.11.10
OR
cvscvsMatch1.11.11
OR
cvscvsMatch1.11.14
OR
cvscvsMatch1.11.15
OR
cvscvsMatch1.11.16
OR
cvscvsMatch1.12.1
OR
cvscvsMatch1.12.2
OR
cvscvsMatch1.12.5
OR
cvscvsMatch1.12.7
OR
cvscvsMatch1.12.8
OR
openpkgopenpkg
OR
openpkgopenpkgMatch1.3
OR
openpkgopenpkgMatch2.0
OR
sgipropackMatch2.4
OR
sgipropackMatch3.0
Node
gentoolinuxMatch1.4
OR
openbsdopenbsd
OR
openbsdopenbsdMatch3.4
OR
openbsdopenbsdMatch3.5

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.5 Medium

AI Score

Confidence

Low

0.931 High

EPSS

Percentile

99.1%