SuSE-SA:2004:008: cvs

This script is Copyright (C) 2004-2010 Tenable Network Security, Inc.


Synopsis :

The remote host is missing a vendor-supplied security patch

Description :

The remote host is missing the patch for the advisory SuSE-SA:2004:008 (cvs).


The Concurrent Versions System (CVS) offers tools which allow developers
to share and maintain large software projects.
During the analyzation of the CVS protocol and their implementation, the
SuSE Security Team discovered a flaw within the handling of pathnames.
Evil CVS servers could specify absolute pathnames during checkouts and
updates, which allows to create arbitrary files with the permissions of
the user invoking the CVS client. This could lead to a compromise of the
system.

Please download the update package for your distribution and verify its
integrity by the methods listed in section 3) of this announcement.
Then, install the package using the command 'rpm -Fhv file.rpm' to apply
the update.

Solution :

http://www.suse.de/security/2004_08_cvs.html

Risk factor :

Medium

Family: SuSE Local Security Checks

Nessus Plugin ID: 13826 ()

Bugtraq ID:

CVE ID:

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now