Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
98

Red Hat Linux 7.3 FLSA:1620 Critical; CVS Remote Denial of Service

Updated cvs packages that fix remote denial of service vulnerabilities are now available. (This is a legacy Red Hat fix, released by the Fedora Project). . Fedora Legacy Update Advisory Synopsis: Updated cvs resolves security vulnerability Advisory ID: FLSA:1620 Issue date: 2004-06-02 Product: Red Hat Linux Keywords: Security Cross references: CVE Names: CAN-2004-0180 CAN-2004-0396 CAN-2004-0405 - ----------------------------------------------------------------------- - --------------------------------------------------------------------- 1. Topic: Updated cvs packages that fix remote denial of service vulnerabilities are now available. 2. Relevent releases/architectures: Red Hat Linux 7.3 - i386 Red Hat Linux 9 - i386 3. Problem description: Sebastian Krahmer discovered a flaw in CVS clients where rcs diff files can create files with absolute pathnames An attacker could create a fake malicious CVS server that would cause arbitrary files to be created or overwritten when a victim connects to it. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0180 to this issue. (Note: Red Hat Linux 9 was already patched for this issue) Derek Price discovered a vulnerability whereby a CVS pserver could be abused by a malicious client to view the contents of certain files outside of the CVS root directory using relative pathnames containing "../". The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0405 to this issue. (Note: Red Hat Linux 9 was already patched for this issue) Stefan Esser discovered a flaw in cvs where malformed "Entry" lines could cause a heap overflow. An attacker who has access to a CVS server could use this flaw to execute arbitrary code under the UID which the CVS server is executing. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0396 to thisissue. Users of CVS are advised to upgrade to these erratum packages, which contain a patch correcting this issue. Fedora Legacy would like to thank David M. Kaplan for bringing these issues to our attention. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via yum and apt. Many people find this an easier way to apply updates. To use yum issue: yum update or to use apt: apt-get update; apt-get upgrade This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. This assumes that you have yum or apt-get configured for obtaining Fedora Legacy content. Please visit for directions on how to configure yum and apt-get. 5. Bug IDs fixed: - 1620 - Security problems found with CVS that need to be fixed. 6. RPMs required: Red Hat Linux 7.3: SRPM: i386: Red Hat Linux 9: SRPM: i386: 7. Verification: SHA1 sum Package Name - --------------------------------------------------------------------------- 58069558fc24abfa50f2ac94327c8d06f234bbd9 7.3/updates/SRPMS/cvs-1.11.1p1-14.legacy.3.src.rpm 523e9f69536d69ae5a8984f4327e35b32c38afdc 7.3/updates/i386/cvs-1.11.1p1-14.legacy.3.i386.rpm 84027d8b84f72c675aeb15816034e86450534b62 9/updates/SRPMS/cvs-1.11.2-23.legacy.src.rpm e79bb82a8dca7a50cf51a72a85879bdbfa0b338d 9/updates/i386/cvs-1.11.2-23.legacy.i386.rpm These packages are GPG signed by Fedora Legacyfor security. Our key is available from org/about/security.php You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the sha1sum with the following command: sha1sum 8. References: CVE -CVE-2004-0180 CVE -CVE-2004-0396 CVE -CVE-2004-0405 https://access.redhat.com/errata/RHSA-2004:153.html https://access.redhat.com/errata/RHSA-2004:190.html 9. Contact: The Fedora Legacy security contact is . More project details at .org . Improved package versions from Fedora address remote connectivity disruption threats through comprehensive safeguarding measures.. Red Hat Linux, CVS Update, Remote Threats, Denial of Service, Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 20, 2023 Critical Red Hat
87

Debian DSA-2407-1 Moderate: CVS Heap Overflow Remote Code Execution

It was discovered that a malicious CVS server could cause a heap overflow in the CVS client, potentially allowing the server to execute arbitrary code on the client. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2407-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Florian Weimer February 09, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : cvs Vulnerability : heap overflow Problem type : remote Debian-specific: no CVE ID : CVE-2012-0804 It was discovered that a malicious CVS server could cause a heap overflow in the CVS client, potentially allowing the server to execute arbitrary code on the client. For the stable distribution (squeeze), this problem has been fixed in version 1:1.12.13-12+squeeze1. For the unstable distribution (sid), this problem has been fixed in version 2:1.12.13+real-7. We recommend that you upgrade your cvs packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A buffer overflow flaw in the FTP server might enable an attacker to run arbitrary commands on user systems. Immediate patching advised.. Debian Security, CVS Update, Heap Overflow, Remote Code, Execution. . LinuxSecurity.com Team

Calendar%202 Feb 09, 2012 Debian
98

Red Hat Enterprise Linux 6: RHSA-2010:0918-01 Moderate: CVS Heap Overflow

An updated cvs package that fixes one security issue is now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: cvs security update Advisory ID: RHSA-2010:0918-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2010:0918.html Issue date: 2010-11-29 CVE Names: CVE-2010-3846 ==================================================================== 1. Summary: An updated cvs package that fixes one security issue is now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 3. Description: Concurrent Version System (CVS) is a version control system that can record the history of your files. An array index error, leading to a heap-based buffer overflow, was found in the way CVS applied certain delta fragment changes from input files in the RCS (Revision Control System file) format. If an attacker in control of a CVS repository stored a specially-crafted RCS file in that repository, and then tricked a remote victim into checking out (updating their CVS repository tree) a revision containing that file, it could lead to arbitrary code execution with the privileges of the CVS server process on the system hosting the CVS repository. (CVE-2010-3846) Red Hat would like to thank Ralph Loader for reporting this issue. All users of cvsare advised to upgrade to this updated package, which contains a backported patch to correct this issue. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 642146 - CVE-2010-3846 cvs: Heap-based buffer overflow by applying RCS file changes 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: i386: cvs-1.11.23-11.el6_0.1.i686.rpm cvs-debuginfo-1.11.23-11.el6_0.1.i686.rpm x86_64: cvs-1.11.23-11.el6_0.1.x86_64.rpm cvs-debuginfo-1.11.23-11.el6_0.1.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: x86_64: cvs-1.11.23-11.el6_0.1.x86_64.rpm cvs-debuginfo-1.11.23-11.el6_0.1.x86_64.rpm Red Hat Enterprise Linux Server (v. 6): Source: i386: cvs-1.11.23-11.el6_0.1.i686.rpm cvs-debuginfo-1.11.23-11.el6_0.1.i686.rpm ppc64: cvs-1.11.23-11.el6_0.1.ppc64.rpm cvs-debuginfo-1.11.23-11.el6_0.1.ppc64.rpm s390x: cvs-1.11.23-11.el6_0.1.s390x.rpm cvs-debuginfo-1.11.23-11.el6_0.1.s390x.rpm x86_64: cvs-1.11.23-11.el6_0.1.x86_64.rpm cvs-debuginfo-1.11.23-11.el6_0.1.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: i386: cvs-1.11.23-11.el6_0.1.i686.rpm cvs-debuginfo-1.11.23-11.el6_0.1.i686.rpm x86_64: cvs-1.11.23-11.el6_0.1.x86_64.rpm cvs-debuginfo-1.11.23-11.el6_0.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2010-3846 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2010 Red Hat, Inc. . Make certain that your Red Hat Enterprise Linux 6 installation is fortified with the mostrecent cvs package update to address the identified security vulnerabilities.. Red Hat Enterprise Linux,CVS Security Update,Heap Overflow. . LinuxSecurity.com Team

Calendar%202 Nov 29, 2010 Red Hat
200

Scientific Linux: CAN-2005-2693 Moderate Security Update for exim and pcre

Moderate: pcre security update. Date: Thu, 8 Sep 2005 16:20:00 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: ERRATA for SL 40,41 x86_64 now available Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. The following ERRATA for SL 40,41 x86_64 are now available from: Synopsis: Low: cvs security update Advisory ID: RHSA-2005:756-01 CVE Names: CAN-2005-2693 cvs-1.11.17-8.RHEL4.x86_64.rpm Synopsis: Moderate: exim security update Advisory ID: RHSA-2005:358-01 Cross references: RHSA-2005:761 CVE Names: CAN-2005-2491 exim-4.43-1.RHEL4.5.x86_64.rpm exim-doc-4.43-1.RHEL4.5.x86_64.rpm exim-mon-4.43-1.RHEL4.5.x86_64.rpm exim-sa-4.43-1.RHEL4.5.x86_64.rpm Synopsis: Moderate: pcre security update Advisory ID: RHSA-2005:761-02 CVE Names: CAN-2005-2491 pcre-4.5-3.2.RHEL4.i386.rpm pcre-4.5-3.2.RHEL4.x86_64.rpm pcre-devel-4.5-3.2.RHEL4.x86_64.rpm --Troy Dawson -- Connie Sieh . Security notice regarding updates for Scientific Linux targeting moderate vulnerabilities across various packages.. Scientific Linux, security advisory, moderate updates, cvs security, exim security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 08, 2005 Important Scientific Linux
98

Red Hat: 2005:756-02 Critical: XSS Vulnerability in Web Application

An updated cvs package that fixes a security bug is now available. This update has been rated as having low security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Low: cvs security update Advisory ID: RHSA-2005:756-01 Advisory URL: https://access.redhat.com/errata/RHSA-2005:756.html Issue date: 2005-09-06 Updated on: 2005-09-06 Product: Red Hat Enterprise Linux CVE Names: CAN-2005-2693 - ---------------------------------------------------------------------1. Summary: An updated cvs package that fixes a security bug is now available. This update has been rated as having low security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Problem description: CVS (Concurrent Version System) is a version control system. An insecure temporary file usage was found in the cvsbug program. It is possible that a local user could leverage this issue to execute arbitrary instructions as the user running cvsbug. The Common Vulnerabilities and Exposures project assigned the name CAN-2005-2693 to this issue. All users of cvs should upgrade to this updated package, which includesa patch to correct this issue. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/): 166365 - CAN-2005-2693 CVS temporary file issue 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 58d707950339b5984b92e679d8735283 cvs-1.11.1p1-19.src.rpm i386: c4c7380ba52df40f08cb1ecc96aa70ea cvs-1.11.1p1-19.i386.rpm ia64: c8f4b3f86b9d2c79a3e6c7be3f68c456 cvs-1.11.1p1-19.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: 58d707950339b5984b92e679d8735283 cvs-1.11.1p1-19.src.rpm ia64: c8f4b3f86b9d2c79a3e6c7be3f68c456 cvs-1.11.1p1-19.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: 58d707950339b5984b92e679d8735283 cvs-1.11.1p1-19.src.rpm i386: c4c7380ba52df40f08cb1ecc96aa70ea cvs-1.11.1p1-19.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: 58d707950339b5984b92e679d8735283 cvs-1.11.1p1-19.src.rpm i386: c4c7380ba52df40f08cb1ecc96aa70ea cvs-1.11.1p1-19.i386.rpm Red Hat Enterprise Linux AS version 3: SRPMS: 63dda99e283a8dec83dda68217cf8242 cvs-1.11.2-28.src.rpm i386: 5a85254a3c83ad082cb9b3579bf53cb1 cvs-1.11.2-28.i386.rpm ia64: e5330fbefb332f44ee8b55ed32cbd580 cvs-1.11.2-28.ia64.rpm ppc: f49d4b23da384c46f13c14a6252910cd cvs-1.11.2-28.ppc.rpm s390: f632e999728a52715479b92de9b49443 cvs-1.11.2-28.s390.rpm s390x: 6f9020e43e5c9129633b96778e476753 cvs-1.11.2-28.s390x.rpm x86_64: dceaf8bbd78dd72d792e0d9ee88a0060 cvs-1.11.2-28.x86_64.rpm Red Hat Desktop version3: SRPMS: 63dda99e283a8dec83dda68217cf8242 cvs-1.11.2-28.src.rpm i386: 5a85254a3c83ad082cb9b3579bf53cb1 cvs-1.11.2-28.i386.rpm x86_64: dceaf8bbd78dd72d792e0d9ee88a0060 cvs-1.11.2-28.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: 63dda99e283a8dec83dda68217cf8242 cvs-1.11.2-28.src.rpm i386: 5a85254a3c83ad082cb9b3579bf53cb1 cvs-1.11.2-28.i386.rpm ia64: e5330fbefb332f44ee8b55ed32cbd580 cvs-1.11.2-28.ia64.rpm x86_64: dceaf8bbd78dd72d792e0d9ee88a0060 cvs-1.11.2-28.x86_64.rpm Red Hat Enterprise Linux WS version 3: SRPMS: 63dda99e283a8dec83dda68217cf8242 cvs-1.11.2-28.src.rpm i386: 5a85254a3c83ad082cb9b3579bf53cb1 cvs-1.11.2-28.i386.rpm ia64: e5330fbefb332f44ee8b55ed32cbd580 cvs-1.11.2-28.ia64.rpm x86_64: dceaf8bbd78dd72d792e0d9ee88a0060 cvs-1.11.2-28.x86_64.rpm Red Hat Enterprise Linux AS version 4: SRPMS: d544d5c637a6d4548afbb8eec213a2d6 cvs-1.11.17-8.RHEL4.src.rpm i386: 175510834dbe9447bed0c56247105667 cvs-1.11.17-8.RHEL4.i386.rpm ia64: a70bd224c537256f89d50839ffee506d cvs-1.11.17-8.RHEL4.ia64.rpm ppc: 45b1d1fc3397f8c484835d6aea963dc8 cvs-1.11.17-8.RHEL4.ppc.rpm s390: 56bbbddb91b8dcae6671cffe4c66e8f1 cvs-1.11.17-8.RHEL4.s390.rpm s390x: 4d66f3e910fb772c21efffaefc8fdbc1 cvs-1.11.17-8.RHEL4.s390x.rpm x86_64: 5f53a4781fe1a688a6af68ef294fe159 cvs-1.11.17-8.RHEL4.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: SRPMS: d544d5c637a6d4548afbb8eec213a2d6 cvs-1.11.17-8.RHEL4.src.rpm i386: 175510834dbe9447bed0c56247105667 cvs-1.11.17-8.RHEL4.i386.rpm x86_64: 5f53a4781fe1a688a6af68ef294fe159 cvs-1.11.17-8.RHEL4.x86_64.rpm Red Hat Enterprise Linux ES version 4: SRPMS: d544d5c637a6d4548afbb8eec213a2d6 cvs-1.11.17-8.RHEL4.src.rpm i386: 175510834dbe9447bed0c56247105667 cvs-1.11.17-8.RHEL4.i386.rpm ia64: a70bd224c537256f89d50839ffee506d cvs-1.11.17-8.RHEL4.ia64.rpm x86_64: 5f53a4781fe1a688a6af68ef294fe159 cvs-1.11.17-8.RHEL4.x86_64.rpm Red Hat Enterprise Linux WS version4: SRPMS: d544d5c637a6d4548afbb8eec213a2d6 cvs-1.11.17-8.RHEL4.src.rpm i386: 175510834dbe9447bed0c56247105667 cvs-1.11.17-8.RHEL4.i386.rpm ia64: a70bd224c537256f89d50839ffee506d cvs-1.11.17-8.RHEL4.ia64.rpm x86_64: 5f53a4781fe1a688a6af68ef294fe159 cvs-1.11.17-8.RHEL4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CAN-2005-2693 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2005 Red Hat, Inc. . New cvs package for CentOS addresses a minor security flaw identified by the CentOS Security Response Team.. Red Hat Security Fix, CVS Update, Security Patch. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Sep 06, 2005 Low Red Hat
98

Red Hat Enterprise Linux: RHSA-2005:387-01 Moderate: CVS Buffer Overflow

An updated cvs package that fixes security bugs is now available. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Moderate: cvs security update Advisory ID: RHSA-2005:387-01 Advisory URL: https://access.redhat.com/errata/RHSA-2005:387.html Issue date: 2005-04-25 Updated on: 2005-04-25 Product: Red Hat Enterprise Linux Keywords: cvs buffer overflow CVE Names: CAN-2005-0753 - ---------------------------------------------------------------------1. Summary: An updated cvs package that fixes security bugs is now available. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Problem description: CVS (Concurrent Version System) is a version control system. A buffer overflow bug was found in the way the CVS client processes version and author information. If a user can be tricked into connecting to a malicious CVS server, an attacker could execute arbitrary code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned thename CAN-2005-0753 to this issue. Additionally, a bug was found in which CVS freed an invalid pointer. However, this issue does not appear to be exploitable. All users of cvs should upgrade to this updated package, which includes a backported patch to correct these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/): 155029 - CAN-2005-0753 multiple issues in cvs 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 6c33701447c66a6dfa27ad3af072a478 cvs-1.11.1p1-18.src.rpm i386: 6f4b84ce418a777eb6644f6ad4d76616 cvs-1.11.1p1-18.i386.rpm ia64: ca0194a275975e9a576e5c643974941d cvs-1.11.1p1-18.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: 6c33701447c66a6dfa27ad3af072a478 cvs-1.11.1p1-18.src.rpm ia64: ca0194a275975e9a576e5c643974941d cvs-1.11.1p1-18.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: 6c33701447c66a6dfa27ad3af072a478 cvs-1.11.1p1-18.src.rpm i386: 6f4b84ce418a777eb6644f6ad4d76616 cvs-1.11.1p1-18.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: 6c33701447c66a6dfa27ad3af072a478 cvs-1.11.1p1-18.src.rpm i386: 6f4b84ce418a777eb6644f6ad4d76616 cvs-1.11.1p1-18.i386.rpm Red Hat Enterprise Linux AS version 3: SRPMS: 3a1c630c467955a5547daeee4384d860 cvs-1.11.2-27.src.rpm i386: 5b821d54dee3d13bab55d246be067be2 cvs-1.11.2-27.i386.rpm ia64: bb679e26359e12c711f31cb05446b798 cvs-1.11.2-27.ia64.rpm ppc: 3bc90cad047c47fa5d53f54f694fd166 cvs-1.11.2-27.ppc.rpm s390: 5f223edfd769dcd3a3c0867304652c16 cvs-1.11.2-27.s390.rpm s390x: 66cf36f6e41c39b05304fbc188294df5 cvs-1.11.2-27.s390x.rpm x86_64: ac9fe80037c3857b51d3ad87f6556503 cvs-1.11.2-27.x86_64.rpm Red Hat Desktop version 3: SRPMS: 3a1c630c467955a5547daeee4384d860 cvs-1.11.2-27.src.rpm i386: 5b821d54dee3d13bab55d246be067be2 cvs-1.11.2-27.i386.rpm x86_64: ac9fe80037c3857b51d3ad87f6556503 cvs-1.11.2-27.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: 3a1c630c467955a5547daeee4384d860 cvs-1.11.2-27.src.rpm i386: 5b821d54dee3d13bab55d246be067be2 cvs-1.11.2-27.i386.rpm ia64: bb679e26359e12c711f31cb05446b798 cvs-1.11.2-27.ia64.rpm x86_64: ac9fe80037c3857b51d3ad87f6556503 cvs-1.11.2-27.x86_64.rpm Red Hat Enterprise Linux WS version 3: SRPMS: 3a1c630c467955a5547daeee4384d860 cvs-1.11.2-27.src.rpm i386: 5b821d54dee3d13bab55d246be067be2 cvs-1.11.2-27.i386.rpm ia64: bb679e26359e12c711f31cb05446b798 cvs-1.11.2-27.ia64.rpm x86_64: ac9fe80037c3857b51d3ad87f6556503 cvs-1.11.2-27.x86_64.rpm Red Hat Enterprise Linux AS version 4: SRPMS: 0a3eaa9dc601fd751d6e11e6aa2f57ad cvs-1.11.17-7.RHEL4.src.rpm i386: a3fb0cdf21e3f1f67acb9580a17b068c cvs-1.11.17-7.RHEL4.i386.rpm ia64: a556e359ecca71df7211becc5189a06f cvs-1.11.17-7.RHEL4.ia64.rpm ppc: 9cdf66a2735a32470680a55c36b4c464 cvs-1.11.17-7.RHEL4.ppc.rpm s390: 569a6322133afdcb7242c18ed17244b3 cvs-1.11.17-7.RHEL4.s390.rpm s390x: c15b1c06582ff0986208955eb8dcfad7 cvs-1.11.17-7.RHEL4.s390x.rpm x86_64: c4fb7c7ef27462e14213d750263ed73f cvs-1.11.17-7.RHEL4.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: SRPMS: 0a3eaa9dc601fd751d6e11e6aa2f57ad cvs-1.11.17-7.RHEL4.src.rpm i386: a3fb0cdf21e3f1f67acb9580a17b068c cvs-1.11.17-7.RHEL4.i386.rpm x86_64: c4fb7c7ef27462e14213d750263ed73f cvs-1.11.17-7.RHEL4.x86_64.rpm Red Hat Enterprise Linux ES version 4: SRPMS: 0a3eaa9dc601fd751d6e11e6aa2f57ad cvs-1.11.17-7.RHEL4.src.rpm i386: a3fb0cdf21e3f1f67acb9580a17b068c cvs-1.11.17-7.RHEL4.i386.rpm ia64: a556e359ecca71df7211becc5189a06f cvs-1.11.17-7.RHEL4.ia64.rpm x86_64: c4fb7c7ef27462e14213d750263ed73f cvs-1.11.17-7.RHEL4.x86_64.rpm Red Hat Enterprise Linux WS version 4: SRPMS: 0a3eaa9dc601fd751d6e11e6aa2f57ad cvs-1.11.17-7.RHEL4.src.rpm i386: a3fb0cdf21e3f1f67acb9580a17b068c cvs-1.11.17-7.RHEL4.i386.rpm ia64: a556e359ecca71df7211becc5189a06f cvs-1.11.17-7.RHEL4.ia64.rpm x86_64: c4fb7c7ef27462e14213d750263ed73f cvs-1.11.17-7.RHEL4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-CAN-2005-0753 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2005 Red Hat, Inc. . A balanced security notice regarding the CVE updates addresses buffer overflow vulnerabilities for CentOS Linux distributions.. Red Hat Security Update, cvs Package Upgrade, Moderate Security Advisory. . LinuxSecurity.com Team

Calendar%202 Apr 26, 2005 Red Hat
89

Fedora: FLSA-1207 Critical: CVS Root Access Exploit Fix

Vulnerabilities allow cvs to write to root filesystem and retain root privileges.. - ----------------------------------------------------------------------- Fedora Legacy Update Advisory Synopsis: Updated cvs resolves security vulnerability Advisory ID: FLSA:1207 Issue date: 2004-01-28 Product: Red Hat Linux Keywords: Security Cross references: CVE Names: CAN-2003-0977 - ----------------------------------------------------------------------- 1. Topic: Updated cvs packages are now available that fix a security vulnerability which may allow cvs to attempt to create files and directories in the root file system, as well as prevent the cvsd from retaining root privileges after a user login. 2. Relevant releases/architectures: Red Hat Linux 7.2 - i386 Red Hat Linux 7.3 - i386 Red Hat Linux 8.0 - i386 3. Problem description: CVS (Concurrent Version System) is a version control system that can record the history of your files (usually, but not always, source code). CVS only stores the differences between versions, instead of every version of every file you have ever created. CVS also keeps a log of who, when, and why changes occurred. A flaw was found in versions of CVS prior to 1.11.10 where a malformed module request could cause the CVS server to attempt to create files or directories at the root level of the file system. However, normal file system permissions would prevent the creation of these misplaced directories. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0977 to this issue. Another flaw was found that would allow the cvsd process to continue to run as root after a user login. Previously, any user with the ability to write the CVSROOT/passwd file could execute arbitrary code as the root user on systems with CVS pserver access enabled. Users of cvs should update to these update packages, which contain a backported security patch that corrects this issue. Fedora Legacy wouldlike to thank Seth Vidal, Jason Rohwedder and Christian Pearce for providing a backported fix for Red Hat Linux 7.2, 7.3, and 8.0. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via yum and apt. Many people find this an easier way to apply updates. To use yum issue: yum update or to use apt: apt-get update; apt-get upgrade This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. This assumes that you have yum or apt-get configured for obtaining Fedora Legacy content. Please visit for directions on how to configure yum and apt-get. 5. Bug IDs fixed: - 1207 - cvs security patches 6. RPMs required: Red Hat Linux 7.2: SRPMS: i386: Red Hat Linux 7.3: SRPMS: i386: Red Hat Linux 8.0: SRPMS: i386: 7. Verification: SHA1 sum Package Name - --------------------------------------------------------------------------- 46da2ca673b3af8a08eab8b1d4322e0d6a9d08ad 7.2/updates/SRPMS/cvs-1.11.1p1-9.7.legacy.src.rpm 469e08276fd61a06f816d4d7df68bc6c85a98560 7.2/updates/i386/cvs-1.11.1p1-9.7.legacy.i386.rpm 46da2ca673b3af8a08eab8b1d4322e0d6a9d08ad 7.3/updates/SRPMS/cvs-1.11.1p1-9.7.legacy.src.rpm 1dfba0ce740a20bd0977eede82f606ea2f907b00 7.3/updates/i386/cvs-1.11.1p1-9.7.legacy.i386.rpm 31e98f14255c132d3f548a51096b0c444a45797a 8.0/updates/SRPMS/cvs-1.11.2-9.legacy.src.rpm e415df08fdfd35216c68651aa5214e7ecdb04268 8.0/updates/i386/cvs-1.11.2-9.legacy.i386.rpm These packages are GPG signed byFedora Legacy for security. Our key is available from You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the sha1sum with the following command: sha1sum 8. References: CVE -CVE-2003-0977 9. Contact: The Fedora Legacy security contact is . More project details at - -- Jesse Keating RHCE ( ) Fedora Legacy Team (http://www.fedoralegacy.org) . Critical security advisory for Fedora addresses CVS root access exploit that may compromise system integrity.. Fedora Updates,CVS Root Access,Security Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 02, 2004 Critical Fedora
99

Slackware: 2003-345-01 Moderate: CVS Server Directory Issue

CVS is a client/server version control system. As a server, it is used to host source code repositories. As a client, it is used to access such repositories. This advisory deals with the use of CVS as a server. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] cvs security update (SSA:2003-345-01) CVS is a client/server version control system. As a server, it is used to host source code repositories. As a client, it is used to access such repositories. This advisory deals with the use of CVS as a server. A security problem which could allow an attacker to create directories and possibly files outside of the CVS repository has been fixed with the release of cvs-1.11.10. Any sites running a CVS server should upgrade to the new CVS package. Here are the details from the Slackware 9.1 ChangeLog: +--------------------------+ Thu Dec 11 12:29:30 PST 2003 patches/packages/cvs-1.11.10-i486-1.tgz: Upgraded to cvs-1.11.10. - From the NEWS file: SERVER SECURITY ISSUES * Malformed module requests could cause the CVS server to attempt to create directories and possibly files at the root of the filesystem holding the CVS repository. Filesystem permissions usually prevent the creation of these misplaced directories, but nevertheless, the CVS server now rejects the malformed requests. (* Security fix *) +--------------------------+ WHERE TO FIND THE NEW PACKAGE: +-----------------------------+ Updated package for Slackware 8.1: Updated package for Slackware 9.0: Updated package for Slackware 9.1: Updated package for Slackware -current: MD5 SIGNATURES: +-------------+ Slackware 8.1 package: 1aff9e868759883f160f7d75800cef63 cvs-1.11.10-i386-1.tgz Slackware 9.0 package: fa213d474908fe0cabd9d41270867eb1 cvs-1.11.10-i386-1.tgz Slackware 9.1 package: e8b66036e4338e18e8d793c1c2b3e3a3 cvs-1.11.10-i486-1.tgz Slackware -current package: 422e1586900f6bf1c363c240fc0368b1 cvs-1.11.10-i486-1.tgz INSTALLATION INSTRUCTIONS: +------------------------+ First, shut downthe cvs server if you are running one. Then, upgrade the package: # upgradepkg cvs-1.11.10-i486-1.tgz Finally, restart the CVS server. +-----+ . Tackling the CVS cybersecurity patch (SSA:2003-345-01) and crucial modifications for CVS server vulnerabilities.. CVS Update, Slackware Advisory, Source Code Security. . LinuxSecurity.com Team

Calendar%202 Dec 11, 2003 Slackware
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200