|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
Description |
Debian CVS contains a flaw that may allow a malicious user to bypass the password protection. The issue is triggered when using the pserver access method in conjunction with the repouid patch, allowing an attacker to to bypass user authentication and gain access to the repository, resulting in a loss of confidentiality.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Authentication Management
Impact:
Loss of Confidentiality
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to version 1.11.1p1debian-10 or higher for stable version or version 1.12.9-11 or higher for unstable, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
CVS
 |
1.11.1p1debian-10 |
1.11.1p1debian-9woody7 |
1.11.1p1debian-9woody6 |
1.11.1p1debian-9woody5 |
1.11.1p1debian-9woody4 |
1.11.1p1debian-9woody3 |
1.11.1p1debian-9woody2 |
1.11.1p1debian-9woody1 |
1.11.1p1debian-9 |
|
|
|
|
|
|
Credit |
- Maks Polunin -
- Alberto Garcia -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|