CVE-2003-0977

CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests.
References
Link Resource
ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc
ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
http://ccvs.cvshome.org/servlets/NewsItemView?newsID=84&JServSessionIdservlets=8u3x1myav1 Patch
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000808
http://marc.info/?l=bugtraq&m=107168035515554&w=2
http://marc.info/?l=bugtraq&m=107540163908129&w=2
http://secunia.com/advisories/10601
http://www.debian.org/security/2004/dsa-422 Patch Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2003:112
http://www.redhat.com/support/errata/RHSA-2004-003.html
http://www.redhat.com/support/errata/RHSA-2004-004.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/13929
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11528
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A855
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A866
ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc
ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
http://ccvs.cvshome.org/servlets/NewsItemView?newsID=84&JServSessionIdservlets=8u3x1myav1 Patch
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000808
http://marc.info/?l=bugtraq&m=107168035515554&w=2
http://marc.info/?l=bugtraq&m=107540163908129&w=2
http://secunia.com/advisories/10601
http://www.debian.org/security/2004/dsa-422 Patch Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2003:112
http://www.redhat.com/support/errata/RHSA-2004-003.html
http://www.redhat.com/support/errata/RHSA-2004-004.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/13929
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11528
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A855
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A866
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cvs:cvs:1.10.7:*:*:*:*:*:*:*
cpe:2.3:a:cvs:cvs:1.10.8:*:*:*:*:*:*:*
cpe:2.3:a:cvs:cvs:1.11:*:*:*:*:*:*:*
cpe:2.3:a:cvs:cvs:1.11.1:*:*:*:*:*:*:*
cpe:2.3:a:cvs:cvs:1.11.1_p1:*:*:*:*:*:*:*
cpe:2.3:a:cvs:cvs:1.11.2:*:*:*:*:*:*:*
cpe:2.3:a:cvs:cvs:1.11.3:*:*:*:*:*:*:*
cpe:2.3:a:cvs:cvs:1.11.4:*:*:*:*:*:*:*
cpe:2.3:a:cvs:cvs:1.11.5:*:*:*:*:*:*:*
cpe:2.3:a:cvs:cvs:1.11.6:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:slackware:slackware_linux:8.1:*:*:*:*:*:*:*
cpe:2.3:o:slackware:slackware_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:slackware:slackware_linux:9.1:*:*:*:*:*:*:*

History

20 Nov 2024, 23:46

Type Values Removed Values Added
References () ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc - () ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc -
References () ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc - () ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc -
References () http://ccvs.cvshome.org/servlets/NewsItemView?newsID=84&JServSessionIdservlets=8u3x1myav1 - Patch () http://ccvs.cvshome.org/servlets/NewsItemView?newsID=84&JServSessionIdservlets=8u3x1myav1 - Patch
References () http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000808 - () http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000808 -
References () http://marc.info/?l=bugtraq&m=107168035515554&w=2 - () http://marc.info/?l=bugtraq&m=107168035515554&w=2 -
References () http://marc.info/?l=bugtraq&m=107540163908129&w=2 - () http://marc.info/?l=bugtraq&m=107540163908129&w=2 -
References () http://secunia.com/advisories/10601 - () http://secunia.com/advisories/10601 -
References () http://www.debian.org/security/2004/dsa-422 - Patch, Vendor Advisory () http://www.debian.org/security/2004/dsa-422 - Patch, Vendor Advisory
References () http://www.mandriva.com/security/advisories?name=MDKSA-2003:112 - () http://www.mandriva.com/security/advisories?name=MDKSA-2003:112 -
References () http://www.redhat.com/support/errata/RHSA-2004-003.html - () http://www.redhat.com/support/errata/RHSA-2004-003.html -
References () http://www.redhat.com/support/errata/RHSA-2004-004.html - () http://www.redhat.com/support/errata/RHSA-2004-004.html -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/13929 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/13929 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11528 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11528 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A855 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A855 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A866 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A866 -

Information

Published : 2004-01-05 05:00

Updated : 2024-11-20 23:46


NVD link : CVE-2003-0977

Mitre link : CVE-2003-0977

CVE.ORG link : CVE-2003-0977


JSON object : View

Products Affected

slackware

  • slackware_linux

cvs

  • cvs