Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

CVS Directory Request Double Free Heap Corruption Vulnerability

It has been reported that a working exploit has been developed by Stefan Esser, but has not been made publicly available.

A program has been released, by Joe Testa <Joe_Testa@rapid7.com>, which is designed to verify vulnerable CVS installations. Further details can be found in the attached reference.

An exploit was also provided by Igor Dobrovitski <noident@mad.scientist.com>.

CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.







 

Privacy Statement
Copyright 2008, SecurityFocus