VulnerabilityModified
CVE-2004-0778
CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which causes different error messages to be returned.
MEDIUM 5.0EPSS 2.40%
Does this matter?
Lower severity and a low EPSS score (2.40%). Track it; it rarely justifies an emergency change on its own.
Description
CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which causes different error messages to be returned.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.40% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- gnu/cvs
- Source
- cve@mitre.org
References
- http://www.idefense.com/application/poi/display?id=130&type=vulnerabilitiesBroken Link, Vendor Advisory
- http://www.kb.cert.org/vuls/id/579225Patch, Third Party Advisory, US Government Resource
- http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:108Broken Link
- http://www.securityfocus.com/bid/10955Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17001Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10688Broken Link
- http://www.idefense.com/application/poi/display?id=130&type=vulnerabilitiesBroken Link, Vendor Advisory
- http://www.kb.cert.org/vuls/id/579225Patch, Third Party Advisory, US Government Resource
- http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:108Broken Link
- http://www.securityfocus.com/bid/10955Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17001Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10688Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.