Re: Fink Security Advisory [#2301200301]: Critical bug in cvs <=1.11.4

David <[email protected]> Thu, 23 Jan 2003 10:57:26 +0100
Newsgroups gmane.os.apple.fink.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: RIPEMD160

=0D
On Donnerstag, J=E4nner 23, 2003, at 10:33  Uhr, David wrote:=0D
=0D
As it seems I stand corrected one more. Double free bugs do not affect  =0D=

Mac OS X, see: http://www.kb.cert.org/vuls/id/650937=0D
=0D
Thank you.=0D
=0D
- -d=0D
=0D
=0D
=0D
> -----BEGIN PGP SIGNED MESSAGE-----=0D
> Hash: RIPEMD160=0D
>=0D
>=0D
> Fink security advisory issued on 23/01/2003=0D
>=0D
>=0D
> Release date:		20/01/2003		=0D
> Package affected: 	cvs <=3D 1.11.4=0D
> Risk: 			Critical=0D
> Type: 			Remote=0D
> Severity:  			A vulnerability within CVS allows remote =
compromise of  =0D
> CVS servers.=0D
> Reference#1:		=
http://security.e-matters.de/advisories/012003.html=0D
> Reference#2:		=
http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCAN-2003- =0D
> 0015=0D
> Package updated:	yes in unstable, no in stable.=0D
>=0D
> Quoting from http://security.e-matters.de/advisories/012003.html=0D
> "...=0D
> Concurrent Versions System (CVS) is the dominant open-source version  =0D=

> control software that allows developers to access the latest code  =0D
> using a network connection. CVS version 1.11.4 and below contain a  =0D=

> flaw that can be used by a remote attacker to execute arbitrary code  =0D=

> on the server.=0D
> .."=0D
> "...=0D
> The impact of this vulnerability depends highly on the configuration  =0D=

> of the server. The CVS server is by default started via inetd with  =0D=

> root privileges. If CVSROOT/passwd is left writeable to the CVS user  =0D=

> this means a remote root compromise. You must also consider that  =0D
> chrooting the CVS daemon may protect the rest of your system against  =0D=

> the intruder but will still leave the whole source tree vulnerable to  =
=0D
> the attacker.=0D
>=0D
> This does vulnerability does not apply to :pserver: method.=0D
> .."=0D
>=0D
> This vulnerability only affects users which choose to offer anonymous  =
=0D
> access to a CVS repository located on one of their computer. If you  =0D=

> are merely using CVS to operate on local or remote CVS repositories  =0D=

> you are not affected by this. However it is suggested that you follow  =
=0D
> the recommendations none the less.=0D
>=0D
> Recommendation:=0D
>=0D
> For users running on the unstable tree of Fink:=0D
>=0D
> The Fink projects recommends that you upgrade your CVS to version  =0D
> 1.11.5 revision 1 if you are offering anonymous CVS services.=0D
> This can easily done by typing  "fink update cvs" .=0D
>=0D
> For users running on the stable tree of Fink:=0D
>=0D
> Users having installed the binary of cvs from Fink are advised to turn =
 =0D
> off anonymous CVS services until a revised version has been added to  =0D=

> the stable tree.=0D
>=0D
>=0D
> -----BEGIN PGP SIGNATURE-----=0D
> Version: GnuPG v1.2.1 (Darwin)=0D
>=0D
> iD8DBQE+L7b8iW/Ta/pxHPQRA1DdAKDfFjAdVJ786foqunI/uqhoIDSImgCfV2mz=0D
> mRbH0BlDIH6EbQk87ySVhlQ=3D=0D
> =3DYIFY=0D
> -----END PGP SIGNATURE-----=0D
>=0D
>=0D
- - "Deep into that darkness peering, long I stood there wondering,  =0D
fearing,=0D
- -  Doubting, dreaming dreams no mortal ever dared to dream to dream  =0D=

before.." Edgar Allen Poe - The Raven=0D
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (Darwin)

iD8DBQE+L7yLiW/Ta/pxHPQRAz3gAKCkVkraftz8gt/bENtsUn6xpQImYQCdH0L1
FiHqA5xNdhZDyX8UysRunxw=3D
=3DAwPh
-----END PGP SIGNATURE-----



-------------------------------------------------------
This SF.NET email is sponsored by:
SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See!
http://www.vasoftware.com