CVS PServer CVSROOT Passwd File Privileged Arbitrary Code Execution Vulnerability
BID:9306
Info
CVS PServer CVSROOT Passwd File Privileged Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 9306 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2003 12:00AM |
| Updated: | Dec 18 2003 12:00AM |
| Credit: | This vulnerability was announced by the vendor. |
| Vulnerable: |
CVS CVS 1.11.10 CVS CVS 1.11.6 CVS CVS 1.11.5 CVS CVS 1.11.4 CVS CVS 1.11.3 CVS CVS 1.11.2 CVS CVS 1.11.1 p1 CVS CVS 1.11.1 CVS CVS 1.11 CVS CVS 1.10.8 CVS CVS 1.10.7 |
| Not Vulnerable: |
CVS CVS 1.11.11 |
Discussion
CVS PServer CVSROOT Passwd File Privileged Arbitrary Code Execution Vulnerability
CVS versions prior to 1.11.11 that are configured to run with pserver access enabled, have been reported prone to an arbitrary code execution vulnerability. The vulnerability may be exploitable by users with specific access levels.
CVS vendors have released a security update. This update supposedly drops root privileges after a user login, to prevent potential privileged code execution.
CVS versions prior to 1.11.11 that are configured to run with pserver access enabled, have been reported prone to an arbitrary code execution vulnerability. The vulnerability may be exploitable by users with specific access levels.
CVS vendors have released a security update. This update supposedly drops root privileges after a user login, to prevent potential privileged code execution.
Exploit / POC
CVS PServer CVSROOT Passwd File Privileged Arbitrary Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
CVS PServer CVSROOT Passwd File Privileged Arbitrary Code Execution Vulnerability
Solution:
The vendor has released an update to address this issue.
Gentoo Linux have advised (200312-08) that all Gentoo Linux users with CVS installed should update their systems to use cvs-1.11.11 or higher. This can be accomplished by issuing the following commands:
emerge sync
emerge -pv '>=dev-util/cvs-1.11.11'
emerge '>=dev-util/cvs-1.11.11'
emerge clean
CVS CVS 1.10.7
CVS CVS 1.10.8
CVS CVS 1.11
CVS CVS 1.11.1 p1
CVS CVS 1.11.1
CVS CVS 1.11.10
CVS CVS 1.11.2
CVS CVS 1.11.3
CVS CVS 1.11.4
CVS CVS 1.11.5
CVS CVS 1.11.6
Solution:
The vendor has released an update to address this issue.
Gentoo Linux have advised (200312-08) that all Gentoo Linux users with CVS installed should update their systems to use cvs-1.11.11 or higher. This can be accomplished by issuing the following commands:
emerge sync
emerge -pv '>=dev-util/cvs-1.11.11'
emerge '>=dev-util/cvs-1.11.11'
emerge clean
CVS CVS 1.10.7
-
CVS cvs-1.11.11.tar.bz2
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=397
CVS CVS 1.10.8
-
CVS cvs-1.11.11.tar.bz2
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=397
CVS CVS 1.11
-
CVS cvs-1.11.11.tar.bz2
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=397
CVS CVS 1.11.1 p1
-
CVS cvs-1.11.11.tar.bz2
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=397
CVS CVS 1.11.1
-
CVS cvs-1.11.11.tar.bz2
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=397
CVS CVS 1.11.10
-
CVS cvs-1.11.11.tar.bz2
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=397
CVS CVS 1.11.2
-
CVS cvs-1.11.11.tar.bz2
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=397
CVS CVS 1.11.3
-
CVS cvs-1.11.11.tar.bz2
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=397
CVS CVS 1.11.4
-
CVS cvs-1.11.11.tar.bz2
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=397
CVS CVS 1.11.5
-
CVS cvs-1.11.11.tar.bz2
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=397
CVS CVS 1.11.6
-
CVS cvs-1.11.11.tar.bz2
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=397