1 |
-----BEGIN PGP SIGNED MESSAGE----- |
2 |
Hash: SHA1 |
3 |
|
4 |
|
5 |
- -------------------------------------------------------------------------- |
6 |
GENTOO LINUX SECURITY ANNOUNCEMENT 200312-04 |
7 |
- -------------------------------------------------------------------------- |
8 |
|
9 |
GLSA: 200312-04 |
10 |
package: dev-util/cvs |
11 |
summary: Fix for malformed module request vulnerability in cvs |
12 |
severity: minimal |
13 |
Gentoo bug: 35371 |
14 |
date: 2003-12-08 |
15 |
CVE: CAN-2003-0977 |
16 |
exploit: unknown |
17 |
affected: <=1.11.9 |
18 |
fixed: >=1.11.10 |
19 |
|
20 |
|
21 |
DESCRIPTION: |
22 |
|
23 |
Quote from <http://ccvs.cvshome.org/servlets/NewsItemView?newsID=84>: |
24 |
|
25 |
Stable CVS 1.11.10 has been released. Stable releases contain only |
26 |
bug fixes from previous versions of CVS. This release fixes a |
27 |
security issue with no known exploits that could cause previous |
28 |
versions of CVS to attempt to create files and directories in the |
29 |
filesystem root. This release also fixes several issues relevant to |
30 |
case insensitive filesystems and some other bugs. We recommend this |
31 |
upgrade for all CVS clients and servers!" |
32 |
|
33 |
|
34 |
SOLUTION: |
35 |
|
36 |
All Gentoo Linux machines with cvs installed should be updated to use |
37 |
cvs-1.11.10 or higher. |
38 |
|
39 |
emerge sync |
40 |
emerge -pv '>=dev-util/cvs-1.11.10' |
41 |
emerge '>=dev-util/cvs-1.11.10' |
42 |
emerge clean |
43 |
|
44 |
|
45 |
// end |
46 |
|
47 |
-----BEGIN PGP SIGNATURE----- |
48 |
Version: GnuPG v1.2.3 (Darwin) |
49 |
|
50 |
iD8DBQE/2BrHnt0v0zAqOHYRAt7HAJ9wVNUmbdvS5H4cyUMufSFLsAuhOACfRGWr |
51 |
SuM+gRSKU69MybE6PRtYSrg= |
52 |
=SQFw |
53 |
-----END PGP SIGNATURE----- |