Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian: DSA-2108-1 Critical: Cvsnt Remote Code Execution Threat

debian
Calendar Grey September 14, 2010
Debian Logo
Debian Security Advisory DSA-2109-2 addresses a gettext flaw allowing unauthorized data exposure. It is advised to update.
It has been discovered that in cvsnt, a multi-platform version of the original source code versioning system CVS, an error in the authentication code allows a malicious, unprivileg...

Summary

It has been discovered that in cvsnt, a multi-platform version of the
original source code versioning system CVS, an error in the
authentication code allows a malicious, unprivileged user, through the
use of a specially crafted branch name, to gain write access to any
module or directory, including CVSROOT itself. The attacker can then
execute arbitrary code as root by modifying or adding administrative
scripts in that directory.

For the stable distribution (lenny), this problem has been fixed in
version 2.5.03.2382-3.3+lenny1.

We recommend that you upgrade your cvsnt package.

Upgrade instructions
- ---------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Lin...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: cvsnt

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here