Loading
CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.
Use Cvs vendor hub and Cvs product page to widen CVE-2004-0414 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2012-0804, CVE-2004-0418 and CVE-2004-0416 for nearby disclosures in the same product family.