Re: cvs-1.11.5: fixes a major security vulnerability in CVS
Billy O'Connor <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Organization | Linux From Scratch |
| Message-ID | <[email protected]> |
[email protected] (Jesse Tie-Ten-Quee) writes: > Yo, > > [16:22:34] <billyoc> HIghoS: new cvs version, security patch. > [16:23:05] <billyoc> "Major security vulnerability". :/ > > No details on specifics. Follow up if you can :) This vulnerability allows readers to become writers, from a quick perusal of the announcement. Will update BLFS immediately, in the meantime, if you're running a cvs server, take a look. http://ccvs.cvshome.org/servlets/NewsItemView?newsID=51&JServSessionIdservlets=v9dwfom8i1 Billy -- Unsubscribe: send email to [email protected] and put 'unsubscribe lfs-security' in the subject header of the message