Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.55276
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-806-1)
Summary:The remote host is missing an update for the Debian 'gcvs' package(s) announced via the DSA-806-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'gcvs' package(s) announced via the DSA-806-1 advisory.

Vulnerability Insight:
Marcus Meissner discovered that the cvsbug program from gcvs, the Graphical frontend for CVS, which serves the popular Concurrent Versions System, uses temporary files in an insecure fashion.

For the old stable distribution (woody) this problem has been fixed in version 1.0a7-2woody1.

For the stable distribution (sarge) this problem has been fixed in version 1.0final-5sarge1.

The unstable distribution (sid) does not expose the cvsbug program.

We recommend that you upgrade your gcvs package.

Affected Software/OS:
'gcvs' package(s) on Debian 3.0, Debian 3.1.

Solution:
Please install the updated package(s).

CVSS Score:
4.6

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-2693
1014857
http://securitytracker.com/id?1014857
16765
http://secunia.com/advisories/16765
ADV-2005-1667
http://www.vupen.com/english/advisories/2005/1667
DSA-802
http://www.debian.org/security/2005/dsa-802
DSA-806
http://www.debian.org/security/2005/dsa-806
FreeBSD-SA-05:20
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:20.cvsbug.asc
RHSA-2005:756
http://www.redhat.com/support/errata/RHSA-2005-756.html
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=166366
oval:org.mitre.oval:def:10835
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10835
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.