Publisher Name: OpenPKG GmbH Publisher Home: http://openpkg.com/ Advisory Id (public): OpenPKG-SA-2003.052 Advisory Type: OpenPKG Security Advisory (SA) Advisory Directory: http://openpkg.com/go/OpenPKG-SA Advisory Document: http://openpkg.com/go/OpenPKG-SA-2003.052 Advisory Published: 2010-02-09 20:10 UTC Issue Id (internal): OpenPKG-SI-20031217.01 Issue First Created: 2003-12-17 Issue Last Modified: 2006-11-28 Issue Revision: 06
Subject Name: CVS Subject Summary: Concurrent Versions Systems (CVS) Subject Home: http://www.cvshome.org/ Subject Versions: * <= 1.12.2 Vulnerability Id: CVE-2003-0977 Vulnerability Scope: global (not OpenPKG specific) Attack Feasibility: run-time Attack Vector: local system Attack Impact: manipulation of data Description: According to a CVS [0] security update [1], a malformed module request can cause the CVS server to attempt to create directories and possibly files at the root of the filesystem holding the CVS repository. Even though filesystem permissions usually prevent the creation of these misplaced directories, the corrected OpenPKG packages include a CVS server which rejects such malformed requests. References: [0] http://www.cvshome.org/ [1] http://ccvs.cvshome.org/servlets/NewsItemView?newsID=85 [2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0977 [3] http://www.openpkg.org/tutorial.html#regular-source [4] http://www.openpkg.org/tutorial.html#regular-binary [5] ftp://ftp.openpkg.org/release/1.2/UPD/cvs-1.11.5-1.2.3.src.rpm [6] ftp://ftp.openpkg.org/release/1.3/UPD/cvs-1.12.1-1.3.1.src.rpm [7] ftp://ftp.openpkg.org/release/1.2/UPD/ [8] ftp://ftp.openpkg.org/release/1.3/UPD/ [9] http://www.openpkg.org/security.html#signature
Primary Package Name: cvs Primary Package Home: http://openpkg.org/go/package/cvs Affected Distribution: Affected Branch: Affected Package: OpenPKG Community 1.2-SOLID cvs-1.11.5-1.2.2 OpenPKG Community 1.3-SOLID cvs-1.12.1-1.3.0 OpenPKG Community CURRENT cvs-1.12.2-20031027 Corrected Distribution: Corrected Branch: Corrected Package: OpenPKG Community 1.2-SOLID cvs-1.11.5-1.2.3 OpenPKG Community 1.3-SOLID cvs-1.12.1-1.3.1 OpenPKG Community CURRENT cvs-1.12.3-20031205