[UNIX] CVS Undocumented Flag Information Disclosure Vulnerability (history.c)
From: SecuriTeam (support_at_securiteam.com)
Date: 08/18/04
- Previous message: SecuriTeam: "[UNIX] PlaySMS SQL Injection via Cookie"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 18 Aug 2004 14:36:31 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
CVS Undocumented Flag Information Disclosure Vulnerability (history.c)
------------------------------------------------------------------------
SUMMARY
CVS (Concurrent Versions System) is "an open-source network-transparent
version control system".
Remote exploitation of an information disclosure vulnerability in
Concurrent Versions Systems (CVS) allows attackers to glean information.
DETAILS
Vulnerable Systems:
* CVS version 1.11 and prior
Immune Systems:
* CV version 1.11.17, version 1.12.9, or newer
The vulnerability exists within an undocumented switch to the 'history'
command implemented in src/history.c. The -X command specifies the name of
the history file allowing an attacker to determine whether arbitrary
system files and directories exist and whether or not the CVS process has
access to them.
Analysis:
Successful exploitation allows remote attackers with credentials to the
affected CVS server to determine whether or not arbitrary system files and
directories exist and are accessible under the permissions of the user
that the CVS daemon runs under.
CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0778>
CAN-2004-0778
Disclosure Timeline:
07/22/2004 Initial vendor notification
07/22/2004 iDEFENSE clients notified
08/05/2004 Initial vendor response
08/16/2004 Public Disclosure
ADDITIONAL INFORMATION
The information has been provided by
<mailto:dlabs-advisories@idefense.com> iDEFENSE.
The original article can be found at:
<http://www.idefense.com/application/poi/display?id=130&type=vulnerabilities&flashstatus=true> http://www.idefense.com/application/poi/display?id=130&type=vulnerabilities&flashstatus=true
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: SecuriTeam: "[UNIX] PlaySMS SQL Injection via Cookie"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- [UNIX] CVS Multiple Vulnerabilities (getline, serve_notify, serve_max_dotdot, wrapper, error_prog_na
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Several new vulnerabilities were
found in the CVS code base after a code ... This "double-free" bug has been exploited
successfully on several Linux ... crashing the CVS server. ... (Securiteam) - [UNIX] CVS Entry Line Flag Heap Overflow
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Stable CVS releases up
to 1.11.15 and CVS feature releases up to 1.12.7 ... can be exploited to execute arbitrary code
on the CVS server. ... unchanged flag insertion into entry lines was discovered.
... (Securiteam) - [UNIX] HTTP Response Splitting and Cross Site Scripting in ViewCVS
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... ViewCVS is "a browser interface
for CVS ... HTTP Response Splitting and Cross Site Scripting in content-type ...
(Securiteam) - [NEWS] Adobe Version Cue VCNative Multiple Vulnerabilities (Privileges Escalation, Symlink Attack)
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... attackers to gain root
privileges and perform a symlink attack using Adobe ... with user-supplied data. ...
(Securiteam) - [NEWS] Gecko Based Browsers Multiple Vulnerabilities (Code Execution, Cross Site Scripting, Window S
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... that allow web sites to
cause arbitrary code execution on users' system ... conduct spoofing and cross site scripting
attacks. ... exploited by attackers to execute arbitrary code. ... (Securiteam)