CVE-2004-1471: High severity Openpkg Openpkg vulnerability
Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a wrapper line.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1471?
CVE-2004-1471 has a high severity rating due to its potential for causing application crashes and executing arbitrary code.
How do I fix CVE-2004-1471?
To fix CVE-2004-1471, upgrade to a version of CVS that is not vulnerable, specifically versions beyond 1.12.8 and 1.11.16.
What types of systems are affected by CVE-2004-1471?
CVE-2004-1471 affects various versions of CVS, including 1.11.x and 1.12.x, as well as Openpkg and SGI ProPack implementations.
What kind of attack can CVE-2004-1471 facilitate?
CVE-2004-1471 allows remote attackers with commit access to use format string specifiers to cause crashes or execute arbitrary commands.
Is CVE-2004-1471 a local or remote vulnerability?
CVE-2004-1471 is classified as a remote vulnerability, as it can be exploited by attackers with CVSROOT commit access.