← Back

CVE-2004-0416

nvd nist
Published: Aug 6, 2004Modified: Apr 16, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.

Affected (29)

Products: Cvs: Cvs · Openpkg: Openpkg · Sgi: Propack · +2 more
Show all products
1 product
Cvs
1 product
Openpkg
1 product
Propack
1 product
Linux
1 product
Openbsd
Configuration A
25 vulnerable
Vulnerable SoftwareAffected Versions
Cvs
Version 1.10.7
Version 1.10.8
Version 1.11.10
Version 1.11.11
Version 1.11.14
Version 1.11.15
Version 1.11.16
Version 1.11.1
Version 1.11.1_p1
Version 1.11.2
Version 1.11.3
Version 1.11.4
Version 1.11.5
Version 1.11.6
Version 1.11
Version 1.12.1
Version 1.12.2
Version 1.12.5
Version 1.12.7
Version 1.12.8
Openpkg
All versions
Version 1.3
Version 2.0
Sgi
Version 2.4
Version 3.0
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.4
Openbsd
All versions
Version 3.4
Version 3.5

References (22)

ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc (unsafe URL)
Source: cve@mitre.org
ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc (unsafe URL)
Source: cve@mitre.org
Source: cve@mitre.org
PatchVendor Advisory
ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.