[UNIX] CVS Server and Client Vulnerabilities (CVSROOT)

From: SecuriTeam (support_at_securiteam.com)
Date: 04/22/04

  • Next message: SecuriTeam: "[NEWS] Vulnerabilities in Cisco's SNMP Message Processing"
    To: list@securiteam.com
    Date: 22 Apr 2004 19:03:39 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      CVS Server and Client Vulnerabilities (CVSROOT)
    ------------------------------------------------------------------------

    SUMMARY

    CVS is "the Concurrent Versions System, the dominant open-source
    network-transparent version control system. CVS is useful for everyone
    from individual developers to large, distributed teams". Two security
    vulnerabilities have been discovered in the product, one in the server
    side of the CVS product and the other in the client side of the CVS
    product.

    DETAILS

    Vulnerable Systems:
     * Netwosix version 1.0
     * Netwosix version 1.1

    Immune Systems:
     * Netwosix version 1.11.15

    Server Security Issues:
     * Piped checkouts of paths above $CVSROOT no longer work. Previously,
    clients could have requested the contents of RCS archive files anywhere on
    a CVS server.

    Client Security Issues:
     * Clients now check paths from the server to verify that they are within
    one of the sandboxes the user requested be updated. Previously, a Trojan
    server could have written or overwritten files anywhere the user had
    access, presenting a serious security risk.

    Solution:
    You can download the latest version of this package in NEPOTE format from:
     <http://www.netwosix.org/0011/nepote> http://www.netwosix.org/0011/nepote

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:derek@ximbiot.com> Derek
    Price.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NEWS] Vulnerabilities in Cisco's SNMP Message Processing"

    Relevant Pages

    • Re: UnauthorizedAccessException when using MSDTC
      ... dispatcher2 is the user logged on the client pc. ... Event Source: Security ... Object Server: SC Manager ... Primary Domain: BLITZ ...
      (microsoft.public.data.ado)
    • Re: Routing and Remote Access - Authentication Failure
      ... because the real client computer can tunel through it's local NAT router, ... travel the Intrenet, join the VPN and access the server, when this feature ... Their security system decided that the server was trying to steel ...
      (microsoft.public.windows.server.networking)
    • Re: WCF security advice (and clarification) needed
      ... You, the client, resolve the foo.mycompany.com hostname within your ... TCP/IP) with that ticket as the security token. ... There are two parties participating in a security scenario, the server ... HTTP supports other authentication ...
      (microsoft.public.dotnet.framework.webservices)
    • RE: Problems with security requirements in Windows WorkGroups.
      ... "A remote side security requirement was not fulfilled during authentication. ... small chat application between a client and a server ... When I try to use the TCP channel I get the error (with NO inner exception ...
      (microsoft.public.dotnet.languages.csharp)
    • Re: VPN -- the next consumer "turnkey"?
      ... I'm not a security expert. ... "A Hamachi system is comprised of backend servers and end-node ... Server nodes track client's locations and provide ... services without providing Hamachi with a list of client IP's. ...
      (alt.internet.wireless)