Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian 2.1: DSA-102385 Critical: Cvsweb Remote Shell Exploit

debian
Calendar Grey July 16, 2000
Debian Logo
-----BEGIN PGP SIGNED MESSAGE----- - ---------------------------------------------------------------
cvsweb is vulnerable to a remote shell exploit.

Summary


Package: cvsweb
Vulnerability type: remote shell
Debian-specific: no

The versions of cvsweb distributed in Debian GNU/Linux 2.1 (aka slink) as
well as in the frozen (potato) and unstable (woody) distributions, are
vulnerable to a remote shell exploit. An attacker with write access to the
cvs repository can execute arbitrary code on the server, as the www-data
user.

The vulnerability is fixed in version 109 of cvsweb for the current stable
release (Debian 2.1), in version 1.79-3potato1 for the frozen distribution,
and in version 1.86-1 for the unstable distribution.

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

Debian GNU/Linux 2.1 alias slink

Source archives:

MD5 checksum: b1810728310882fb72078674521ee369

MD5 checksum: 4c42ec3ba7248fc2499cdfaa6ae6b702

Architecture indendent archives:

MD5 checksum: fe9144254ab224923ac627aef7ec2167

Debian GNU/Linux 2.2 alias potato

Please note that potato has not been releas...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here