Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2003:009: cvs Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the cvs package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2003:009 (cvs).
Two vulnerabilities were discoverd by Stefen Esser in the cvs program. The first
is an exploitable double free() bug within the server, which can be used to
execute arbitray code on the CVS server. To accomplish this, the attacker must
have an anonymous read-only login to the CVS server. The second vulnerability is
with the Checkin-prog and Update-prog commands. If a client has write
permission, he can use these commands to execute programs outside of the scope
of CVS, the output of which will be sent as output to the client.
This update fixes the double free() vulnerability and removes the Checkin-prog
and Update-prog commands from CVS.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2003:009
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.