Description: | Description:
The remote host is missing updates announced in advisory RHSA-2004:004.
CVS is a version control system frequently used to manage source code repositories.
A flaw was found in versions of CVS prior to 1.11.10 where a malformed module request could cause the CVS server to attempt to create files or directories at the root level of the file system. However, normal file system permissions would prevent the creation of these misplaced directories. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2003-0977 to this issue.
Users of CVS are advised to upgrade to these erratum packages, which contain a patch correcting this issue.
For Red Hat Enterprise Linux 2.1, these updates also fix an off-by-one overflow in the CVS PreservePermissions code. The PreservePermissions feature is not used by default (and can only be used for local CVS). The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2002-0844 to this issue.
Solution: Please note that this update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date
http://rhn.redhat.com/errata/RHSA-2004-004.html http://ccvs.cvshome.org/servlets/NewsItemView?newsID=84 http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0081.html
Risk factor : High
CVSS Score: 7.5
|