5.1 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:H/Au:N/C:P/I:P/A:P
7.5 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
8 High
AI Score
Confidence
High
0.101 Low
EPSS
Percentile
94.9%
Package : cvs
Version : 2:1.12.13+real-9+deb7u1
CVE ID : CVE-2017-12836
Debian Bug : #871810
It was discovered that there was a command injection vulnerability in the CVS
revision control system.
For Debian 7 "Wheezy", this issue has been fixed in cvs version
2:1.12.13+real-9+deb7u1.
We recommend that you upgrade your cvs packages. Thanks to Thorsten Glaser
<[email protected]> for preparing and testing this upload.
Regards,
,''`.
: :' : Chris Lamb
`. `'` [email protected] / chris-lamb.co.uk
`-
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 9 | i386 | cvs | < 2:1.12.13+real-22+deb9u1 | cvs_2:1.12.13+real-22+deb9u1_i386.deb |
Debian | 9 | mipsel | cvs-dbgsym | < 2:1.12.13+real-22+deb9u1 | cvs-dbgsym_2:1.12.13+real-22+deb9u1_mipsel.deb |
Debian | 8 | kfreebsd-amd64 | cvs | < 2:1.12.13+real-15+deb8u1 | cvs_2:1.12.13+real-15+deb8u1_kfreebsd-amd64.deb |
Debian | 9 | amd64 | cvs | < 2:1.12.13+real-22+deb9u1 | cvs_2:1.12.13+real-22+deb9u1_amd64.deb |
Debian | 7 | armhf | cvs | < 2:1.12.13+real-9+deb7u1 | cvs_2:1.12.13+real-9+deb7u1_armhf.deb |
Debian | 8 | kfreebsd-i386 | cvs | < 2:1.12.13+real-15+deb8u1 | cvs_2:1.12.13+real-15+deb8u1_kfreebsd-i386.deb |
Debian | 9 | mips64el | cvs | < 2:1.12.13+real-22+deb9u1 | cvs_2:1.12.13+real-22+deb9u1_mips64el.deb |
Debian | 8 | mipsel | cvs | < 2:1.12.13+real-15+deb8u1 | cvs_2:1.12.13+real-15+deb8u1_mipsel.deb |
Debian | 8 | s390x | cvs | < 2:1.12.13+real-15+deb8u1 | cvs_2:1.12.13+real-15+deb8u1_s390x.deb |
Debian | 7 | all | cvs | < 2:1.12.13+real-9+deb7u1 | cvs_2:1.12.13+real-9+deb7u1_all.deb |
5.1 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:H/Au:N/C:P/I:P/A:P
7.5 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
8 High
AI Score
Confidence
High
0.101 Low
EPSS
Percentile
94.9%