|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
|
CVS Home Information for VU#680620
| Date Notified | |
| Date Modified | 04/05/2007 08:45:33 AM |
| Status Summary | Vulnerable |
Vendor StatementNo statement is currently available from the vendor regarding this vulnerability.US-CERT AddendumFrom the CVS version 1.12.13 NEWS file:
CVS now uses version 1.2.3 of the ZLib compression libraries in order to avoid two recently announced security vulnerabilities in them. Both may be used for denial of service attacks and one may reportedly allow execution of arbitrary code, though this is not confirmed. Please see the CERT vulnerabilities advisories #238678 <http://www.kb.cert.org/vuls/id/238678> & #680620 <http://www.kb.cert.org/vuls/id/680620> for more.
Note that according to CVS HOME, CVS development and the CVS information pages have moved to http://www.nongnu.org/cvs/.
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |