APP: CVS Directory Heap Overflow
This signature detects attempts to exploit a known vulnerability against the double free () function in Concurrent Versions System protocol. Attackers sending an over long directory name can cause a heap double free on some CVS systems.
Extended Description
CVS is prone to a double free vulnerability in the Directory requests. An attacker may potentially take advantage of this issue to cause heap memory to be corrupted with attacker-supplied values, which may result in execution of arbitrary code.
Affected Products
Sun cobalt_raq_550,Freebsd freebsd
srx-branch-19.3
vsrx3bsd-19.2
srx-19.4
vsrx3bsd-19.4
srx-branch-19.4
vsrx-19.4
vsrx-19.2
srx-19.3
srx-branch-12.3
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx-12.3
vmx-19.3
srx-12.3
Sun
Cvs
Freebsd
7.5