MEDIUM · 5.0

CVE-2004-0417

Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could ...

Vulnerability Description

Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
CvsCvs1.10.7
OpenpkgOpenpkgAll versions
SgiPropack2.4
GentooLinux1.4
OpenbsdOpenbsdAll versions

References

FAQ

What is CVE-2004-0417?

CVE-2004-0417 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could ...

How severe is CVE-2004-0417?

CVE-2004-0417 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0417?

Check the references section above for vendor advisories and patch information. Affected products include: Cvs Cvs, Openpkg Openpkg, Sgi Propack, Gentoo Linux, Openbsd Openbsd.