KDE 3.1 Final in fink unstable now.

David <[email protected]> Wed, 29 Jan 2003 01:47:17 +0100
Newsgroups gmane.os.apple.fink.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: RIPEMD160


Fink security advisory issued on 23/01/2003


Release date:		20/01/2003		
Package affected: 	cvs <= 1.11.4
Risk: 			Critical
Type: 			Remote
Severity:  			A vulnerability within CVS allows remote compromise of  
CVS servers.
Reference#1:		http://security.e-matters.de/advisories/012003.html
Reference#2:		http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003- 
0015
Package updated:	yes in unstable, no in stable.

Quoting from http://security.e-matters.de/advisories/012003.html
"...
Concurrent Versions System (CVS) is the dominant open-source version  
control software that allows developers to access the latest code using  
a network connection. CVS version 1.11.4 and below contain a flaw that  
can be used by a remote attacker to execute arbitrary code on the  
server.
.."
"...
The impact of this vulnerability depends highly on the configuration of  
the server. The CVS server is by default started via inetd with root  
privileges. If CVSROOT/passwd is left writeable to the CVS user this  
means a remote root compromise. You must also consider that chrooting  
the CVS daemon may protect the rest of your system against the intruder  
but will still leave the whole source tree vulnerable to the attacker.

This does vulnerability does not apply to :pserver: method.
.."

This vulnerability only affects users which choose to offer anonymous  
access to a CVS repository located on one of their computer. If you are  
merely using CVS to operate on local or remote CVS repositories you are  
not affected by this. However it is suggested that you follow the  
recommendations none the less.

Recommendation:

For users running on the unstable tree of Fink:

The Fink projects recommends that you upgrade your CVS to version  
1.11.5 revision 1 if you are offering anonymous CVS services.
This can easily done by typing  "fink update cvs" .

For users running on the stable tree of Fink:

Users having installed the binary of cvs from Fink are advised to turn  
off anonymous CVS services until a revised version has been added to  
the stable tree.


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (Darwin)

iD8DBQE+L7b8iW/Ta/pxHPQRA1DdAKDfFjAdVJ786foqunI/uqhoIDSImgCfV2mz
mRbH0BlDIH6EbQk87ySVhlQ=
=YIFY
-----END PGP SIGNATURE-----



-------------------------------------------------------
This SF.NET email is sponsored by:
SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See!
http://www.vasoftware.com