RSS   Vulnerabilities for 'Monotone'   RSS

2010-10-27
 
CVE-2010-4098

CWE-DesignError
 

 
monotone before 0.48.1, when configured to allow remote commands, allows remote attackers to cause a denial of service (crash) via an empty argument to the mtn command.

 
2006-03-12
 
CVE-2006-1166

 

 
Monotone 0.25 and earlier, when a user creates a file in a directory called "mt", and when checking out that file on a case-insensitive file system such as Windows or Mac OS X, places the file into the "MT" bookkeeping directory, which could allow context-dependent attackers to execute arbitrary Lua programs as the user running monotone.

 


Copyright 2024, cxsecurity.com

 

Back to Top