Executive Summary

Summary
Titlecvs security update
Informations
NameDSA-2407First vendor Publication2012-02-09
VendorDebianLast vendor Modification2012-02-09
Severity (Vendor) N/ARevision1

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score10Attack RangeNetwork
Cvss Impact Score10Attack ComplexityLow
Cvss Expoit Score10AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

It was discovered that a malicious CVS server could cause a heap overflow in the CVS client, potentially allowing the server to execute arbitrary code on the client.

For the stable distribution (squeeze), this problem has been fixed in version 1:1.12.13-12+squeeze1.

For the unstable distribution (sid), this problem has been fixed in version 2:1.12.13+real-7.

We recommend that you upgrade your cvs packages.

Original Source

Url : http://www.debian.org/security/2012/dsa-2407

CWE : Common Weakness Enumeration

idName
CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer

CPE : Common Platform Enumeration

TypeDescriptionCount
Application2