Nessus Plugin #15323

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

[DSA486] DSA-486-1 cvs

Family:
Debian Local Security Checks
Category:
infos
Copyright:
This script is (C) 2004 Michel Arboi
Summary:
DSA-486-1 cvs
Version:
$Revision: 1.4 $
Cve_id:
CAN-2004-0180, CAN-2004-0405
Bugtraq_id:
10138, 10140
Xrefs:
DSA:486
Description:

Two vulnerabilities have been discovered and fixed in CVS:
Sebastian Krahmer discovered a vulnerability whereby
a malicious CVS pserver could create arbitrary files on the client
system during an update or checkout operation, by supplying absolute
pathnames in RCS diffs.
Derek Robert Price discovered a vulnerability whereby
a CVS pserver could be abused by a malicious client to view the
contents of certain files outside of the CVS root directory using
relative pathnames containing "../".
For the current stable distribution (woody) these problems have been
fixed in version 1.11.1p1debian-9woody2.
For the unstable distribution (sid), these problems will be fixed soon.
We recommend that you update your cvs package.


Solution : http://www.debian.org/security/2004/dsa-486
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.