Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

APP:CVS:ENTRY-TAG-OF

Severity

High

Recommended

No

Recommended Action

Drop

Category

APP

Keywords

CVS Entry Line Tag Heap Overflow

Release Date

2004/05/26

Update Number

1213

Supported Platforms

idp-4.1+, isg-3.5+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

APP: CVS Entry Line Tag Heap Overflow


This signature detects attempts to exploit a known vulnerability against Concurrent Versions System (CVS). Because CVS does not handle flag attachments correctly, attackers can send a malicious request to the CVS server to overwrite CVS memory, create a denial-of-service (DoS), or execute arbitrary code. To exploit this vulnerability, the attacker must use valid login ID and password for the CVS server, but an anonymous, read-only account is sufficient.

Extended Description

CVS is prone to a remote heap overflow vulnerability. This issue presents itself during the handling of user-supplied input for entry lines with 'modified' and 'unchanged' flags. This vulnerability can allow an attacker to overflow a vulnerable buffer on the heap, possibly leading to arbitrary code execution. CVS versions 1.11.15 and prior and CVS feature versions 1.12.7 and prior are prone to this issue. **UPDATE: Symantec has confirmed that this vulnerability is being actively exploited in the wild. Administrators are urged to upgrade and block external access to potentially vulnerable servers, if possible.

Affected Products

  • CVS 1.10.7
  • CVS 1.10.8
  • CVS 1.11.0
  • CVS 1.11.1
  • CVS 1.11.10
  • CVS 1.11.11
  • CVS 1.11.14
  • CVS 1.11.15
  • CVS 1.11.1 P1
  • CVS 1.11.2
  • CVS 1.11.3
  • CVS 1.11.4
  • CVS 1.11.5
  • CVS 1.11.6
  • CVS 1.12.1
  • CVS 1.12.2
  • CVS 1.12.5
  • CVS 1.12.7
  • Gentoo Linux 1.4.0
  • NetBSD 1.6.0
  • NetBSD 1.6.1
  • NetBSD 1.6.2
  • NetBSD Current

References

  • BugTraq: 10384
  • CVE: CVE-2004-0396
  • URL: http://www.securiteam.com/unixfocus/5HP0E2KCUU.html
  • URL: http://www.us-cert.gov/cas/techalerts/TA04-147A.html

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out