Re: CVSNT Security Note 5871 (CVE-2010-1326)

"Arthur Barrett" <arthur.barrett-qn/[email protected]> Fri, 24 Sep 2010 11:41:12 +1100
Newsgroups gmane.comp.version-control.cvs.tortoisecvs.user
Message-ID <[email protected]>
We've been receiving a few e-mails this week about this issue in the
Community Edition of TortoiseCVS - apparently if you have the Secunia
software installed it will now alert you of this problem.  

So therefore I thought it may be worth sending a reminder:

1. TortoiseCVS is a 'front end' to CVSNT

2. Many versions of TortoiseCVS include CVSNT with a known security
issue CVE-2010-1326

3. A fix is included in CVS Suite 2009 which also includes our enhanced
TortoiseCVS
   trial edition available here:
   http://march-hare.com/cvspro/

4. A fix is included in TortoiseCVS 1.12 RC
   http://www.tortoisecvs.org/download.shtml

Previous announcement regarding the security issue is below.  

Please do not contact me directly about this issue.

Regards,


Arthur Barrett


> -----Original Message-----
> From: Arthur Barrett 
> Sent: Thursday, 15 April 2010 4:31 PM
> To: tortoisecvs-users-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
> Subject: [TortoiseCVS] CVSNT Security Note 5871 (CVE-2010-1326)
> 
> 
> 
> During regular auditing and maintenance of our source code we have
> discovered a serious security issue with CVSNT  which affects CVSNT
> 2.0.58 and later (including all builds of 2.5.01, 2.5.02, 
> 2.5.03 before build 3736 and 2.5.04 releases before build 2862; 
> CVS Suite 2.5.03, CVS Suite 2008 before build 3736 (and CVS Suite 
> 2009 pre-releases before 3729) and has a proven exploit.
> 
> We recommend you upgrade to:
> * CVSNT Low Performance Community Server 2.5.05.3744, or
> * CVS Suite Server 2008 [2.5.03.3736] or 
> * CVS Suite High Performance Server 2009 [2.8.01.3759 or 2.8.01.3761]
> 
> More details are available here, including the complete list 
> of affected versions:
> http://march-hare.com/cvspro/vuln.htm
> 
> We have already notified the maintainers of the list of Common
> Vulnerabilities and Exposures and they have assigned the candidate
> CVE-2010-1326 to this issue.
> 
> If you are a support customer then you can download the 
> update from the customer area of the march-hare.com web 
> site and discuss any problems with the support team.  
> Please do not contact me directly about this issue.
> 
> Regards,
> 
> 
> Arthur Barrett
> Product Manager

------------------------------------------------------------------------------
Nokia and AT&T present the 2010 Calling All Innovators-North America contest
Create new apps & games for the Nokia N8 for consumers in  U.S. and Canada
$10 million total in prizes - $4M cash, 500 devices, nearly $6M in marketing
Develop with Nokia Qt SDK, Web Runtime, or Java and Publish to Ovi Store 
http://p.sf.net/sfu/nokia-dev2dev