CVE-2004-1471

Published Dec 31, 2004

Last updated 7 years ago

Overview

Description
Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a wrapper line.
Source
cve@mitre.org
NVD status
Modified

Risk scores

CVSS 2.0

Type
Primary
Base score
7.1
Impact score
10
Exploitability score
3.9
Vector string
AV:N/AC:H/Au:S/C:C/I:C/A:C

Weaknesses

nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Evaluator

Comment
-
Impact
Failed exploit attempts will likely cause a denial of service condition.
Solution
Failed exploit attempts will likely cause a denial of service condition.

Configurations