|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
Description |
CVS contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when a user with write access to the repository sends a malformed directory name and makes special use of the "update-prog" and "checkin-prog" commands to execute arbitrary code on the server with the priveleges of the running CVS server. If CVSROOT/passwd has been left as writeable this results in a root compromise. This flaw may lead to a loss of Confidentiality, Integrity and/or Availability.
|
|
Classification |
Unknown or Incomplete
|
|
Solution |
Upgrade to version 1.11.11 (stable) or 1.12.5 (feature) or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
CVS
 |
Unknown or Unspecified |
|
|
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|