Security Issues with WinCVS / CVSNT

"'Arthur Barrett' [email protected] [cvsgui]" <[email protected]> Wed, 26 Aug 2015 15:08:44 +1000
Newsgroups gmane.comp.version-control.cvs.gui.user
Message-ID <[email protected]>
Just a quick reminder that the 'old' versions of CVSNT shipped with
WinCVS have known security vulnerabilities:
https://www.march-hare.com/cvspro/security.htm

CVSNT is the software that actually does the 'checkout' and 'commit'
operations - you can 'see' it running in the 'progress' window in
WinCVS.  CVSNT client is bundled with WinCVS.  WinCVS is the 'GUI' that
gives you the menu and dialog boxes.  WinCVS itself does not do any
version control, that's what the CVSNT client is doing.

In particular the CVSNT client (and hence WinCVS) is susceptible to the
recent 'wipe SSH-2 private keys from memory' and 'diffie-hellman range
check' security issues.
http://march-hare.com/cvspro/security.htm#CVE-2015-2157

CVS Suite 2009R2 (CVSNT 2.8.01) was updated on 3rd August 2015 to
resolve this.  

CVS Suite 2009R2 client contains WinCVS, TortoiseCVS, CVS Suite Studio,
Release Manager etc. and is compatible with Windows 8, Windows 7,
Windows Vista and Windows XP.

CVS Suite 2009R2 command line client is compatible with Linux, Mac and
Windows.

CVS Suite 2009R2 server contains the high performance server service,
integration with Jira, Bugzilla and Mantis, failsafe audit, change and
merge tracking and is compatible with Linux, Mac, and Windows Server
2012R2, Windows Server 2012, Windows Server 2008R2, Windows Server 2008
and Windows Server 2003.

For more information please contact [email protected]

Regards,


Arthur Barrett
Product Manager
March Hare Software
authors of CVSNT since 2004	


------------------------------------
Posted by: "Arthur Barrett" <[email protected]>
------------------------------------