Description: | Description:
The remote host is missing updates announced in advisory FLSA-2004:1620.
Sebastian Krahmer discovered a flaw in CVS clients where rcs diff files can create files with absolute pathnames An attacker could create a fake malicious CVS server that would cause arbitrary files to be created or overwritten when a victim connects to it. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0180 to this issue. (Note: Red Hat Linux 9 was already patched for this issue)
Derek Price discovered a vulnerability whereby a CVS pserver could be abused by a malicious client to view the contents of certain files outside of the CVS root directory using relative pathnames containing ../. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0405 to this issue. (Note: Red Hat Linux 9 was already patched for this issue)
Stefan Esser discovered a flaw in cvs where malformed Entry lines could cause a heap overflow. An attacker who has access to a CVS server could use this flaw to execute arbitrary code under the UID which the CVS server is executing. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0396 to this issue.
Users of CVS are advised to upgrade to these erratum packages, which contain a patch correcting this issue.
Fedora Legacy would like to thank David M. Kaplan for bringing these issues to our attention.
Affected platforms: Redhat 7.3 Redhat 9
Solution: http://www.securityspace.com/smysecure/catid.html?in=FLSA-2004:1620 http://rhn.redhat.com/errata/RHSA-2004-153.html http://rhn.redhat.com/errata/RHSA-2004-190.html http://rhn.redhat.com/errata/RHSA-2004-154.html
Risk factor : High
CVSS Score: 7.5
|