[UNIX] CVS Server and Client Vulnerabilities (CVSROOT)
From: SecuriTeam (support_at_securiteam.com)
Date: 04/22/04
- Previous message: SecuriTeam: "[NEWS] Vulnerability in the TCP Protocol Allows RST Spoofing (Cisco Advisory)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 22 Apr 2004 19:03:39 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
CVS Server and Client Vulnerabilities (CVSROOT)
------------------------------------------------------------------------
SUMMARY
CVS is "the Concurrent Versions System, the dominant open-source
network-transparent version control system. CVS is useful for everyone
from individual developers to large, distributed teams". Two security
vulnerabilities have been discovered in the product, one in the server
side of the CVS product and the other in the client side of the CVS
product.
DETAILS
Vulnerable Systems:
* Netwosix version 1.0
* Netwosix version 1.1
Immune Systems:
* Netwosix version 1.11.15
Server Security Issues:
* Piped checkouts of paths above $CVSROOT no longer work. Previously,
clients could have requested the contents of RCS archive files anywhere on
a CVS server.
Client Security Issues:
* Clients now check paths from the server to verify that they are within
one of the sandboxes the user requested be updated. Previously, a Trojan
server could have written or overwritten files anywhere the user had
access, presenting a serious security risk.
Solution:
You can download the latest version of this package in NEPOTE format from:
<http://www.netwosix.org/0011/nepote> http://www.netwosix.org/0011/nepote
ADDITIONAL INFORMATION
The information has been provided by <mailto:derek@ximbiot.com> Derek
Price.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: SecuriTeam: "[NEWS] Vulnerability in the TCP Protocol Allows RST Spoofing (Cisco Advisory)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|