CVE-2004-0418

Description

From CVE.org

serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.

Acknowledgements

Red Hat would like to thank Sebastian Krahmer and Stefan Esser for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.