Family: Gentoo Local Security Checks --> Category: infos
[GLSA-200412-26] ViewCVS: Information leak and XSS vulnerabilities Vulnerability Scan
Vulnerability Scan Summary
ViewCVS: Information leak and XSS vulnerabilities
Detailed Explanation for this Vulnerability Test
The remote host is affected by the vulnerability described in GLSA-200412-26
(ViewCVS: Information leak and XSS vulnerabilities)
The tar export functions in ViewCVS bypass the 'hide_cvsroot' and
'forbidden' settings and therefore expose information that should be
kept secret (CVE-2004-0915). Furthermore, some error messages in
ViewCVS do not filter user-provided information, making it vulnerable
to a cross-site scripting attack (CVE-2004-1062).
By using the tar export functions, a remote attacker could access
information that is configured as restricted. Through the use of a
malicious request, a possible hacker could also inject and execute malicious
script code, potentially compromising another user's browser.
There is no known workaround at this time.
All ViewCVS users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/viewcvs-0.9.2_p20041207-r1"
Threat Level: Low
Click HERE for more information and discussions on this network vulnerability scan.