monotone before 0.48.1, when configured to allow remote commands, allows remote attackers to cause a denial of service (crash) via an empty argument to the mtn command.
Link | Tags |
---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050468.html | vendor advisory |
http://www.monotone.ca/NEWS | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/62758 | vdb entry |
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050484.html | vendor advisory |
http://www.vupen.com/english/advisories/2010/2910 | vdb entry |
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00005.html | vendor advisory |
http://www.securityfocus.com/bid/44383 | vdb entry |
http://secunia.com/advisories/41960 | third party advisory vendor advisory |
http://secunia.com/advisories/42177 | third party advisory |