← Back

CVE-2004-1471

nvd nist
Published: Dec 31, 2004Modified: Apr 16, 2026

JSON object

Loading...
7.1
Vector
AV:N/AC:H/Au:S/C:C/I:C/A:C
Exploitability: 3.9 / Impact: 10.0
Source: NVD

Description

Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a wrapper line.

Affected (111)

Products: Cvs: Cvs · Openpkg: Openpkg · Sgi: Propack · +3 more
Show all products
1 product
Cvs
1 product
Openpkg
1 product
Propack
1 product
Freebsd
1 product
Linux
1 product
Openbsd
Configuration A
25 vulnerable
Vulnerable SoftwareAffected Versions
Cvs
Version 1.10.7
Version 1.10.8
Version 1.11.10
Version 1.11.11
Version 1.11.14
Version 1.11.15
Version 1.11.16
Version 1.11.1
Version 1.11.1_p1
Version 1.11.2
Version 1.11.3
Version 1.11.4
Version 1.11.5
Version 1.11.6
Version 1.11
Version 1.12.1
Version 1.12.2
Version 1.12.5
Version 1.12.7
Version 1.12.8
Openpkg
Version 1.3
Version 2.0
Version current
Sgi
Version 2.4
Version 3.0
Configuration B
86 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 1.1.5.1
Version 2.0.5
Version 2.0
Version 2.1.0
Version 2.1.5
Version 2.1.6.1
Version 2.1.6
Version 2.1.7.1
Version 2.2.2
Version 2.2.3
Version 2.2.4
Version 2.2.5
Version 2.2.6
Version 2.2.8
Version 2.2
Version 3.0
Version 3.0 releng
Version 3.1
Version 3.2
Version 3.3
Version 3.4
Version 3.5.1
Version 3.5.1 release
Version 3.5.1 stable
Version 3.5
Version 3.5 stable
Version 4.0
Version 4.0 alpha
Version 4.0 releng
Version 4.1.1
Version 4.1.1 release
Version 4.1.1 stable
Version 4.10
Version 4.10 release
Version 4.10 releng
Version 4.1
Version 4.2
Version 4.2 stable
Version 4.3
Version 4.3 release
Version 4.3 release_p38
Version 4.3 releng
Version 4.3 stable
Version 4.4
Version 4.4 release_p42
Version 4.4 releng
Version 4.4 stable
Version 4.5
Version 4.5 release
Version 4.5 release_p32
Version 4.5 releng
Version 4.5 stable
Version 4.6.2
Version 4.6
Version 4.6 release
Version 4.6 release_p20
Version 4.6 releng
Version 4.6 stable
Version 4.7
Version 4.7 release
Version 4.7 release_p17
Version 4.7 releng
Version 4.7 stable
Version 4.8
Version 4.8 pre-release
Version 4.8 release_p6
Version 4.8 releng
Version 4.9
Version 4.9 pre-release
Version 4.9 releng
Version 5.0
Version 5.0 alpha
Version 5.0 release_p14
Version 5.0 releng
Version 5.1
Version 5.1 alpha
Version 5.1 release
Version 5.1 release_p5
Version 5.1 releng
Version 5.2.1 release
Version 5.2.1 releng
Version 5.2
Version 1.4
Openbsd
Version 3.4
Version 3.5
Version current

References (10)

ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:14.cvs.asc (unsafe URL)
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Patch
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:14.cvs.asc (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.