CVSps Unfiltered Escape Sequence Vulnerability
BID:7288
Info
CVSps Unfiltered Escape Sequence Vulnerability
| Bugtraq ID: | 7288 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 05 2003 12:00AM |
| Updated: | Apr 05 2003 12:00AM |
| Credit: | This vulnerability was reported in the product changelog. |
| Vulnerable: |
CVSps CVSps 2.0 b9 CVSps CVSps 2.0 b8 CVSps CVSps 2.0 b7 CVSps CVSps 2.0 b6 |
| Not Vulnerable: |
CVSps CVSps 2.0 b10 |
Discussion
CVSps Unfiltered Escape Sequence Vulnerability
A vulnerability has been reported for CVSps where some characters were improperly filtered prior to sending them to the command shell.
When CVSps is used to process the malicious CVS repository, it may be possible to execute commands on the underlying shell of the host.
A vulnerability has been reported for CVSps where some characters were improperly filtered prior to sending them to the command shell.
When CVSps is used to process the malicious CVS repository, it may be possible to execute commands on the underlying shell of the host.
Solution / Fix
CVSps Unfiltered Escape Sequence Vulnerability
Solution:
Fixes available:
CVSps CVSps 2.0 b6
CVSps CVSps 2.0 b9
CVSps CVSps 2.0 b7
CVSps CVSps 2.0 b8
Solution:
Fixes available:
CVSps CVSps 2.0 b6
-
CVSps cvsps-2.0b10.tar.gz
http://www.cobite.com/cvsps/cvsps-2.0b10.tar.gz
CVSps CVSps 2.0 b9
-
CVSps cvsps-2.0b10.tar.gz
http://www.cobite.com/cvsps/cvsps-2.0b10.tar.gz
CVSps CVSps 2.0 b7
-
CVSps cvsps-2.0b10.tar.gz
http://www.cobite.com/cvsps/cvsps-2.0b10.tar.gz
CVSps CVSps 2.0 b8
-
CVSps cvsps-2.0b10.tar.gz
http://www.cobite.com/cvsps/cvsps-2.0b10.tar.gz