Re: Fink Security Advisory [#2301200301]: Critical bug in cvs <=1.11.4
David <[email protected]> Thu, 23 Jan 2003 10:57:26 +0100
| Newsgroups | gmane.os.apple.fink.announce |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: RIPEMD160 =0D On Donnerstag, J=E4nner 23, 2003, at 10:33 Uhr, David wrote:=0D =0D As it seems I stand corrected one more. Double free bugs do not affect =0D= Mac OS X, see: http://www.kb.cert.org/vuls/id/650937=0D =0D Thank you.=0D =0D - -d=0D =0D =0D =0D > -----BEGIN PGP SIGNED MESSAGE-----=0D > Hash: RIPEMD160=0D >=0D >=0D > Fink security advisory issued on 23/01/2003=0D >=0D >=0D > Release date: 20/01/2003 =0D > Package affected: cvs <=3D 1.11.4=0D > Risk: Critical=0D > Type: Remote=0D > Severity: A vulnerability within CVS allows remote = compromise of =0D > CVS servers.=0D > Reference#1: = http://security.e-matters.de/advisories/012003.html=0D > Reference#2: = http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCAN-2003- =0D > 0015=0D > Package updated: yes in unstable, no in stable.=0D >=0D > Quoting from http://security.e-matters.de/advisories/012003.html=0D > "...=0D > Concurrent Versions System (CVS) is the dominant open-source version =0D= > control software that allows developers to access the latest code =0D > using a network connection. CVS version 1.11.4 and below contain a =0D= > flaw that can be used by a remote attacker to execute arbitrary code =0D= > on the server.=0D > .."=0D > "...=0D > The impact of this vulnerability depends highly on the configuration =0D= > of the server. The CVS server is by default started via inetd with =0D= > root privileges. If CVSROOT/passwd is left writeable to the CVS user =0D= > this means a remote root compromise. You must also consider that =0D > chrooting the CVS daemon may protect the rest of your system against =0D= > the intruder but will still leave the whole source tree vulnerable to = =0D > the attacker.=0D >=0D > This does vulnerability does not apply to :pserver: method.=0D > .."=0D >=0D > This vulnerability only affects users which choose to offer anonymous = =0D > access to a CVS repository located on one of their computer. If you =0D= > are merely using CVS to operate on local or remote CVS repositories =0D= > you are not affected by this. However it is suggested that you follow = =0D > the recommendations none the less.=0D >=0D > Recommendation:=0D >=0D > For users running on the unstable tree of Fink:=0D >=0D > The Fink projects recommends that you upgrade your CVS to version =0D > 1.11.5 revision 1 if you are offering anonymous CVS services.=0D > This can easily done by typing "fink update cvs" .=0D >=0D > For users running on the stable tree of Fink:=0D >=0D > Users having installed the binary of cvs from Fink are advised to turn = =0D > off anonymous CVS services until a revised version has been added to =0D= > the stable tree.=0D >=0D >=0D > -----BEGIN PGP SIGNATURE-----=0D > Version: GnuPG v1.2.1 (Darwin)=0D >=0D > iD8DBQE+L7b8iW/Ta/pxHPQRA1DdAKDfFjAdVJ786foqunI/uqhoIDSImgCfV2mz=0D > mRbH0BlDIH6EbQk87ySVhlQ=3D=0D > =3DYIFY=0D > -----END PGP SIGNATURE-----=0D >=0D >=0D - - "Deep into that darkness peering, long I stood there wondering, =0D fearing,=0D - - Doubting, dreaming dreams no mortal ever dared to dream to dream =0D= before.." Edgar Allen Poe - The Raven=0D -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (Darwin) iD8DBQE+L7yLiW/Ta/pxHPQRAz3gAKCkVkraftz8gt/bENtsUn6xpQImYQCdH0L1 FiHqA5xNdhZDyX8UysRunxw=3D =3DAwPh -----END PGP SIGNATURE----- ------------------------------------------------------- This SF.NET email is sponsored by: SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See! http://www.vasoftware.com