Unrated severityNVD Advisory· Published Aug 6, 2004· Updated Apr 16, 2026
CVE-2004-0417
CVE-2004-0417
Description
Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.
Affected products
29cpe:2.3:a:cvs:cvs:1.10.7:*:*:*:*:*:*:*+ 19 more
- cpe:2.3:a:cvs:cvs:1.10.7:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.10.8:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.11:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.11.1:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.11.10:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.11.11:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.11.14:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.11.15:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.11.16:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.11.1_p1:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.11.2:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.11.3:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.11.4:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.11.5:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.11.6:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.12.1:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.12.2:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.12.5:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.12.7:*:*:*:*:*:*:*
- cpe:2.3:a:cvs:cvs:1.12.8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.debian.org/security/2004/dsa-519nvdPatchVendor Advisory
- security.gentoo.org/glsa/glsa-200406-06.xmlnvdVendor Advisory
- patches.sgi.com/support/free/security/advisories/20040605-01-U.ascnvd
- lists.grok.org.uk/pipermail/full-disclosure/2004-June/022441.htmlnvd
- marc.infonvd
- security.e-matters.de/advisories/092004.htmlnvd
- www.mandriva.com/security/advisoriesnvd
- www.redhat.com/support/errata/RHSA-2004-233.htmlnvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1001nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11145nvd
News mentions
0No linked articles in our index yet.