Summary
The remote host seems to be running cvstrac,
a web-based bug and patch-set tracking system for CVS.
This version contains a flaw related to the history_update() function in history.c that may allow an attacker to cause a buffer overflow and execute arbitrary code on the remote system.
***** OVS has determined the vulnerability exists on the target ***** simply by looking at the version number(s) of CVSTrac ***** installed there.
Solution
Update to version 1.1.4 or disable this CGI suite
Severity
Classification
-
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Adobe ColdFusion Components (CFC) Denial Of Service Vulnerability
- Apache Tomcat/JBoss EJBInvokerServlet / JMXInvokerServlet (RMI over HTTP) Marshalled Object Remote Code Execution
- Arkeia Appliance Multiple Vulnerabilities
- Apple Safari RSS Feed Information Disclosure Vulnerability
- A Really Simple Chat Multiple SQL Injection Vulnerabilities