CVS history.c File Existence Information Disclosure

This script is Copyright (C) 2004-2011 Tenable Network Security, Inc.


Synopsis :

The remote CVS server is affected by an information disclosure
vulnerability.

Description :

The remote CVS server, according to its version number, can be
exploited by malicious users to gain knowledge of certain system
information.

This behavior can be exploited to determine the existence and
permissions of arbitrary files and directories on a vulnerable system.

See also :

http://www.nessus.org/u?7a576d49
http://www.nessus.org/u?66a25c2a

Solution :

Upgrade to CVS 1.11.17 and 1.12.9, or newer.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS Temporal Score : 4.3
(CVSS2#E:H/RL:OF/RC:C)
Public Exploit Available : true

Family: Misc.

Nessus Plugin ID: 14313 (cvs_file_existence_info_weak.nasl)

Bugtraq ID: 10955

CVE ID: CVE-2004-0778