Lucene search

K
osvGoogleOSV:DSA-486
HistoryApr 16, 2004 - 12:00 a.m.

cvs - several vulnerabilities

2004-04-1600:00:00
Google
osv.dev
12

0.011 Low

EPSS

Percentile

84.5%

Two vulnerabilities have been discovered and fixed in CVS:

  • CAN-2004-0180
    Sebastian Krahmer discovered a vulnerability whereby
    a malicious CVS pserver could create arbitrary files on the client
    system during an update or checkout operation, by supplying absolute
    pathnames in RCS diffs.

  • CAN-2004-0405
    Derek Robert Price discovered a vulnerability whereby
    a CVS pserver could be abused by a malicious client to view the
    contents of certain files outside of the CVS root directory using
    relative pathnames containing “…/”.

For the current stable distribution (woody) these problems have been
fixed in version 1.11.1p1debian-9woody2.

For the unstable distribution (sid), these problems will be fixed soon.

We recommend that you update your cvs package.