Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2004:028: cvs Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the cvs package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2004:028 (cvs).
Sebastian Krahmer from the SUSE security team discovered a remotely exploitable
vulnerability in the CVS client. When doing a cvs checkout or update over a
network, the client accepts absolute pathnames in the RCS diff files. A
maliciously configured server could then create any file with content on the
local user's disk. This problem affects all versions of CVS prior to 1.11.15
which has fixed the problem.
The updated packages provide 1.11.14 with the pertinent fix for the problem.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2004:028
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.