Re: cvs-1.11.5: fixes a major security vulnerability in CVS

Billy O'Connor <[email protected]>
Newsgroups gmane.linux.lfs.security
Organization Linux From Scratch
Message-ID <[email protected]>
[email protected] (Jesse Tie-Ten-Quee) writes:

> Yo,
>
> On Mon, Jan 20, 2003 at 04:47:59PM -0500, Billy O'Connor wrote:
>> http://ccvs.cvshome.org/servlets/NewsItemView?newsID=51&JServSessionIdservlets=v9dwfom8i1
>
> The official announcement by e-matters (whom found this);
>
> http://security.e-matters.de/advisories/012003.html
>
> Man... this just scares me.  *goes to patch quasar's cvs even further :)*
>

Digging through the ChangeLogs for the cvs tree, it seems that this
vulnerability goes back at least as far as 1997.  :/
-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.