CVS Directory Request Double Free Heap Corruption Vulnerability
BID:6650
Info
CVS Directory Request Double Free Heap Corruption Vulnerability
| Bugtraq ID: | 6650 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0015 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 20 2003 12:00AM |
| Updated: | Jul 11 2009 07:17PM |
| Credit: | This vulnerability was discovered by Stefan Esser of e-matters. |
| Vulnerable: |
Sun Linux 5.0.3 Sun Cobalt RaQ XTR Sun Cobalt RaQ 550 Sun Cobalt RaQ 4 Sun Cobalt RaQ 3 Sun Cobalt RaQ 2 Sun Cobalt Qube 3 Sun Cobalt Qube 2 Sun Cobalt CacheRaQ 4 Sun Cobalt CacheRaQ 3 FreeBSD FreeBSD 5.0 FreeBSD FreeBSD 4.7 FreeBSD FreeBSD 4.6 FreeBSD FreeBSD 4.5 FreeBSD FreeBSD 4.4 CVS CVS 1.11.4 CVS CVS 1.11.3 CVS CVS 1.11.2 CVS CVS 1.11.1 p1 CVS CVS 1.11.1 CVS CVS 1.11 CVS CVS 1.10.8 CVS CVS 1.10.7 CrossWind CyberScheduler 1.10.7 |
| Not Vulnerable: |
CVS CVS 1.11.5 |
Exploit / POC
CVS Directory Request Double Free Heap Corruption Vulnerability
It has been reported that a working exploit has been developed by Stefan Esser, but has not been made publicly available.
A program has been released, by Joe Testa <[email protected]>, which is designed to verify vulnerable CVS installations. Further details can be found in the attached reference.
An exploit was also provided by Igor Dobrovitski <[email protected]>.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
It has been reported that a working exploit has been developed by Stefan Esser, but has not been made publicly available.
A program has been released, by Joe Testa <[email protected]>, which is designed to verify vulnerable CVS installations. Further details can be found in the attached reference.
An exploit was also provided by Igor Dobrovitski <[email protected]>.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.