|
CVS Directory Request Double Free Heap Corruption Vulnerability
It has been reported that a working exploit has been developed by Stefan Esser, but has not been made publicly available. A program has been released, by Joe Testa <Joe_Testa@rapid7.com>, which is designed to verify vulnerable CVS installations. Further details can be found in the attached reference. An exploit was also provided by Igor Dobrovitski <noident@mad.scientist.com>. CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild. |
|
|
Privacy Statement |