Re: cvs-1.11.5: fixes a major security vulnerability in CVS

Billy O'Connor <[email protected]>
Newsgroups gmane.linux.lfs.security
Organization Linux From Scratch
Message-ID <[email protected]>
[email protected] (Jesse Tie-Ten-Quee) writes:

> Yo,
>
> [16:22:34] <billyoc> HIghoS: new cvs version, security patch.
> [16:23:05] <billyoc> "Major security vulnerability".  :/
>
> No details on specifics.  Follow up if you can :)

This vulnerability allows readers to become writers, from a quick
perusal of the announcement.  Will update BLFS immediately, in the
meantime, if you're running a cvs server, take a look.

http://ccvs.cvshome.org/servlets/NewsItemView?newsID=51&JServSessionIdservlets=v9dwfom8i1

Billy
-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.