KDE 3.1 Final in fink unstable now.
David <[email protected]> Wed, 29 Jan 2003 01:47:17 +0100
| Newsgroups | gmane.os.apple.fink.announce |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: RIPEMD160 Fink security advisory issued on 23/01/2003 Release date: 20/01/2003 Package affected: cvs <= 1.11.4 Risk: Critical Type: Remote Severity: A vulnerability within CVS allows remote compromise of CVS servers. Reference#1: http://security.e-matters.de/advisories/012003.html Reference#2: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003- 0015 Package updated: yes in unstable, no in stable. Quoting from http://security.e-matters.de/advisories/012003.html "... Concurrent Versions System (CVS) is the dominant open-source version control software that allows developers to access the latest code using a network connection. CVS version 1.11.4 and below contain a flaw that can be used by a remote attacker to execute arbitrary code on the server. .." "... The impact of this vulnerability depends highly on the configuration of the server. The CVS server is by default started via inetd with root privileges. If CVSROOT/passwd is left writeable to the CVS user this means a remote root compromise. You must also consider that chrooting the CVS daemon may protect the rest of your system against the intruder but will still leave the whole source tree vulnerable to the attacker. This does vulnerability does not apply to :pserver: method. .." This vulnerability only affects users which choose to offer anonymous access to a CVS repository located on one of their computer. If you are merely using CVS to operate on local or remote CVS repositories you are not affected by this. However it is suggested that you follow the recommendations none the less. Recommendation: For users running on the unstable tree of Fink: The Fink projects recommends that you upgrade your CVS to version 1.11.5 revision 1 if you are offering anonymous CVS services. This can easily done by typing "fink update cvs" . For users running on the stable tree of Fink: Users having installed the binary of cvs from Fink are advised to turn off anonymous CVS services until a revised version has been added to the stable tree. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (Darwin) iD8DBQE+L7b8iW/Ta/pxHPQRA1DdAKDfFjAdVJ786foqunI/uqhoIDSImgCfV2mz mRbH0BlDIH6EbQk87ySVhlQ= =YIFY -----END PGP SIGNATURE----- ------------------------------------------------------- This SF.NET email is sponsored by: SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See! http://www.vasoftware.com