CVE-2004-0405
EPSS 1.4%
Description
CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180.
How to fix CVE-2004-0405
To remediate CVE-2004-0405, upgrade the affected package to a fixed version below.
- Debian/cvs—upgrade to 1:1.12.5-4 or later
Is CVE-2004-0405 being exploited?
Low — EPSS is 1.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1:1.12.5-4