CVS.Argumentx.Command.Double.Free.Heap.Corruption

description-logoDescription

CVS (Concurrent Versions System) has a double free vulnerability. An attacker can exploit it with the command "Argumentx" without any arguments. This issue may allow remote attackers to execute arbitrary code.

affected-products-logoAffected Products

CVS (Concurrent Versions System) 1.11.16 and earlier.
CVS (Concurrent Versions System) 1.12.8 and earlier.

Impact logoImpact

System compromise: possible remote code execution.

recomended-action-logoRecommended Actions

Upgrade to the latest version, available from Web site:

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)