Solution
Please Install the Updated Packages.
Insight
Concurrent Version System (CVS) is a version control system that can record the history of your files.
A heap-based buffer overflow flaw was found in the way the CVS client handled responses from HTTP proxies. A malicious HTTP proxy could use this flaw to cause the CVS client to crash or, possibly, execute arbitrary code with the privileges of the user running the CVS client. (CVE-2012-0804)
All users of cvs are advised to upgrade to these updated packages, which contain a patch to correct this issue.
Affected
cvs on CentOS 6
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2012-0804 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities