CVE-2004-0778: Medium severity GNU Cvs vulnerability
CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which causes different error messages to be returned.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0778?
CVE-2004-0778 is considered a moderate severity vulnerability that allows remote attackers to detect the existence of arbitrary files and directories.
How do I fix CVE-2004-0778?
To fix CVE-2004-0778, upgrade CVS to version 1.11.17 or later for 1.11.x series and version 1.12.9 or later for 1.12.x series.
What systems are affected by CVE-2004-0778?
CVE-2004-0778 affects various versions of CVS including 1.10.6 through 1.12.8.
Can CVE-2004-0778 be exploited remotely?
Yes, CVE-2004-0778 can be exploited remotely, allowing attackers to gather information about file structures.
What is the main impact of CVE-2004-0778?
The main impact of CVE-2004-0778 is the disclosure of file existence, which could lead to further attacks on the system.