Re: cvs-1.11.5: fixes a major security vulnerability in CVS
Billy O'Connor <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Organization | Linux From Scratch |
| Message-ID | <[email protected]> |
[email protected] (Jesse Tie-Ten-Quee) writes: > Yo, > > On Mon, Jan 20, 2003 at 04:47:59PM -0500, Billy O'Connor wrote: >> http://ccvs.cvshome.org/servlets/NewsItemView?newsID=51&JServSessionIdservlets=v9dwfom8i1 > > The official announcement by e-matters (whom found this); > > http://security.e-matters.de/advisories/012003.html > > Man... this just scares me. *goes to patch quasar's cvs even further :)* > Digging through the ChangeLogs for the cvs tree, it seems that this vulnerability goes back at least as far as 1997. :/ -- Unsubscribe: send email to [email protected] and put 'unsubscribe lfs-security' in the subject header of the message