CVE Database


Impact: Critical
Public: 2004-05-19


The MITRE CVE dictionary describes this issue as:

Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.

Find out more about CVE-2004-0396 from the MITRE CVE dictionary and NIST NVD.

Red Hat security errata

Platform Errata Release Date
Red Hat Enterprise Linux version 2.1 (cvs) RHSA-2004:190 May 19, 2004
Red Hat Enterprise Linux version 3 (cvs) RHSA-2004:190 May 19, 2004

External References


Red Hat would like to thank Stefan Esser for notifying us of this issue and Derek Price for providing an updated patch.

This page is generated automatically and has not been checked for errors or omissions.

For clarification or corrections please contact the Red Hat Security Response Team.