Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Debian Local Security Checks --> Category: infos

[DSA486] DSA-486-1 cvs Vulnerability Scan


Vulnerability Scan Summary
DSA-486-1 cvs

Detailed Explanation for this Vulnerability Test

Two vulnerabilities have been discovered and fixed in CVS:
Sebastian Krahmer discovered a vulnerability whereby
a malicious CVS pserver could create arbitrary files on the client
system during an update or checkout operation, by supplying absolute
pathnames in RCS diffs.
Derek Robert Price discovered a vulnerability whereby
a CVS pserver could be abused by a malicious client to view the
contents of certain files outside of the CVS root directory using
relative pathnames containing "../".
For the current stable distribution (woody) these problems have been
fixed in version 1.11.1p1debian-9woody2.
For the unstable distribution (sid), these problems will be fixed soon.
We recommend that you update your cvs package.


Solution : http://www.debian.org/security/2004/dsa-486
Threat Level: High

Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.