>> CVSTrac "is_eow()" Commit Message Handling Remote Denial of Service Vulnerability
Title : CVSTrac "is_eow()" Commit Message Handling Remote Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2007-0398 CVE ID : CVE-2007-0347
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-29
Technical Description
A vulnerability has been identified in CVSTrac, which could be exploited by remote attackers to cause a denial of service. This issue is due to an error in the "is_eow()" [format.c] function when handling malformed commit messages, tickets or Wiki pages, which could be exploited by attackers with check-in permissions and Wiki or ticket edit permissions to create a denial of service condition.