CVE-2010-3846

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
05/11/2010
Last modified:
11/04/2025

Description

Array index error in the apply_rcs_change function in rcs.c in CVS 1.11.23 allows local users to gain privileges via an RCS file containing crafted delta fragment changes that trigger a heap-based buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nongnu:cvs:1.11.23:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools