← Back

CVE-2004-0418

nvd nist
Published: Aug 6, 2004Modified: Apr 16, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.

Affected (29)

Products: Cvs: Cvs · Openpkg: Openpkg · Sgi: Propack · +2 more
Show all products
1 product
Cvs
1 product
Openpkg
1 product
Propack
1 product
Linux
1 product
Openbsd
Configuration A
25 vulnerable
Vulnerable SoftwareAffected Versions
Cvs
Version 1.10.7
Version 1.10.8
Version 1.11.10
Version 1.11.11
Version 1.11.14
Version 1.11.15
Version 1.11.16
Version 1.11.1
Version 1.11.1_p1
Version 1.11.2
Version 1.11.3
Version 1.11.4
Version 1.11.5
Version 1.11.6
Version 1.11
Version 1.12.1
Version 1.12.2
Version 1.12.5
Version 1.12.7
Version 1.12.8
Openpkg
All versions
Version 1.3
Version 2.0
Sgi
Version 2.4
Version 3.0
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.4
Openbsd
All versions
Version 3.4
Version 3.5

References (22)

ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc (unsafe URL)
Source: cve@mitre.org
ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc (unsafe URL)
Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
ftp://patches.sgi.com/support/free/security/advisories/20040605-01-U.asc (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.