// For flags

CVE-2003-0015

CVS 1.11.x - Directory Request Double-Free Heap Corruption

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-prog commands.

Vulnerabilidad de doble liberación de memoria en CVS 1.11.4 y anteriores permite a atacantes remotos causar una denegación de servicio y posiblemente ejecutar código arbitrario mediante una petición de de directorio mal formada, como ha sido demostrado evitando las comprobaciones de escritura para ejecutar los comandos Update-prog y Checkin-prog.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2003-01-07 CVE Reserved
  • 2003-01-20 First Exploit
  • 2003-01-23 CVE Published
  • 2024-08-08 CVE Updated
  • 2024-09-16 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-415: Double Free
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Freebsd
Search vendor "Freebsd"
Freebsd
Search vendor "Freebsd" for product "Freebsd"
4.4
Search vendor "Freebsd" for product "Freebsd" and version "4.4"
-
Affected
Freebsd
Search vendor "Freebsd"
Freebsd
Search vendor "Freebsd" for product "Freebsd"
4.5
Search vendor "Freebsd" for product "Freebsd" and version "4.5"
-
Affected
Freebsd
Search vendor "Freebsd"
Freebsd
Search vendor "Freebsd" for product "Freebsd"
4.6
Search vendor "Freebsd" for product "Freebsd" and version "4.6"
-
Affected
Freebsd
Search vendor "Freebsd"
Freebsd
Search vendor "Freebsd" for product "Freebsd"
4.7
Search vendor "Freebsd" for product "Freebsd" and version "4.7"
-
Affected
Freebsd
Search vendor "Freebsd"
Freebsd
Search vendor "Freebsd" for product "Freebsd"
5.0
Search vendor "Freebsd" for product "Freebsd" and version "5.0"
-
Affected
Cvs
Search vendor "Cvs"
Cvs
Search vendor "Cvs" for product "Cvs"
1.10.7
Search vendor "Cvs" for product "Cvs" and version "1.10.7"
-
Affected
Cvs
Search vendor "Cvs"
Cvs
Search vendor "Cvs" for product "Cvs"
1.10.8
Search vendor "Cvs" for product "Cvs" and version "1.10.8"
-
Affected
Cvs
Search vendor "Cvs"
Cvs
Search vendor "Cvs" for product "Cvs"
1.11
Search vendor "Cvs" for product "Cvs" and version "1.11"
-
Affected
Cvs
Search vendor "Cvs"
Cvs
Search vendor "Cvs" for product "Cvs"
1.11.1
Search vendor "Cvs" for product "Cvs" and version "1.11.1"
-
Affected
Cvs
Search vendor "Cvs"
Cvs
Search vendor "Cvs" for product "Cvs"
1.11.1p1
Search vendor "Cvs" for product "Cvs" and version "1.11.1p1"
-
Affected
Cvs
Search vendor "Cvs"
Cvs
Search vendor "Cvs" for product "Cvs"
1.11.2
Search vendor "Cvs" for product "Cvs" and version "1.11.2"
-
Affected
Cvs
Search vendor "Cvs"
Cvs
Search vendor "Cvs" for product "Cvs"
1.11.3
Search vendor "Cvs" for product "Cvs" and version "1.11.3"
-
Affected
Cvs
Search vendor "Cvs"
Cvs
Search vendor "Cvs" for product "Cvs"
1.11.4
Search vendor "Cvs" for product "Cvs" and version "1.11.4"
-
Affected