Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Gentoo GLSA-202311-17 High Risk: Git Repo DoS and Code Execution

gentoo
Calendar Grey June 10, 2004
Scroller Gentoo
Investigate recent security flaws in CVS impacting Gentoo Linux and crucial enhancements to safeguard your operating environment.
Several serious new vulnerabilities have been found in CVS, which may allow an attacker to remotely compromise a CVS server.

Summary

Gentoo Linux Security Advisory GLSA 200406-06 https://security.gentoo.org/ Severity: High Title: CVS: additional DoS and arbitrary code execution vulnerabilities Date: June 10, 2004 Bugs: #53408 ID: 200406-06

Synopsis ======= Several serious new vulnerabilities have been found in CVS, which may allow an attacker to remotely compromise a CVS server.
Background ========= CVS (Concurrent Versions System) is an open-source network-transparent version control system. It contains both a client utility and a server.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-util/cvs <= 1.11.16-r1 >= 1.11.17
========== A team audit of the CVS source code performed by Stefan Esser and Sebastian Kra...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround