CVE-2010-3846

Array index error in the apply_rcs_change function in rcs.c in CVS 1.11.23 allows local users to gain privileges via an RCS file containing crafted delta fragment changes that trigger a heap-based buffer overflow.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nongnu:cvs:1.11.23:*:*:*:*:*:*:*

History

13 Feb 2023, 04:26

Type Values Removed Values Added
Summary CVE-2010-3846 cvs: Heap-based buffer overflow by applying RCS file changes Array index error in the apply_rcs_change function in rcs.c in CVS 1.11.23 allows local users to gain privileges via an RCS file containing crafted delta fragment changes that trigger a heap-based buffer overflow.
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2010:0918', 'name': 'https://access.redhat.com/errata/RHSA-2010:0918', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2010-3846', 'name': 'https://access.redhat.com/security/cve/CVE-2010-3846', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 17:17

Type Values Removed Values Added
Summary Array index error in the apply_rcs_change function in rcs.c in CVS 1.11.23 allows local users to gain privileges via an RCS file containing crafted delta fragment changes that trigger a heap-based buffer overflow. CVE-2010-3846 cvs: Heap-based buffer overflow by applying RCS file changes
References
  • (MISC) https://access.redhat.com/errata/RHSA-2010:0918 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2010-3846 -

Information

Published : 2010-11-05 17:00

Updated : 2023-12-10 11:03


NVD link : CVE-2010-3846

Mitre link : CVE-2010-3846

CVE.ORG link : CVE-2010-3846


JSON object : View

Products Affected

nongnu

  • cvs
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer