Lucene search

K
redhatRedHatRHSA-2003:013
HistoryFeb 06, 2003 - 12:00 a.m.

(RHSA-2003:013) cvs security update

2003-02-0600:00:00
access.redhat.com
13

0.296 Low

EPSS

Percentile

96.9%

CVS is a version control system frequently used to manage source code
repositories. During an audit of the CVS sources, Stefan Esser discovered
an exploitable double-free bug in the CVS server.

On servers which are configured to allow anonymous read-only access, this
bug could be used by anonymous users to gain write privileges. Users with
CVS write privileges can then use the Update-prog and Checkin-prog features
to execute arbitrary commands on the server.

All users of CVS are advised to upgrade to these packages which
contain patches to correct the double-free bug.

Our thanks go to Stefan Esser of e-matters for reporting this issue to us.

OSVersionArchitecturePackageVersionFilename
RedHatanyi386cvs< 1.11.1p1-8.7cvs-1.11.1p1-8.7.i386.rpm
RedHatanyia64cvs< 1.11.1p1-8.7cvs-1.11.1p1-8.7.ia64.rpm