CVE-2012-0804

Publication date 9 February 2012

Last updated 24 July 2024


Ubuntu priority

Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP response.

Read the notes from the security team

Status

Package Ubuntu Release Status
cvs 11.10 oneiric
Fixed 2:1.12.13+real-6ubuntu0.1
11.04 natty
Fixed 1:1.12.13-12ubuntu1.11.04.1
10.10 maverick
Fixed 1:1.12.13-12ubuntu1.10.10.1
10.04 LTS lucid
Fixed 1:1.12.13-12ubuntu1.10.04.1
8.04 LTS hardy Ignored end of life

Notes


mdeslaur

DSA-2407-1

References

Related Ubuntu Security Notices (USN)

Other references