OpenPKG Security Advisory
OpenPKG-SA-2006.014
Publisher Name: OpenPKG GmbH
Publisher Home: http://openpkg.com/
Advisory Id (public): OpenPKG-SA-2006.014
Advisory Type: OpenPKG Security Advisory (SA)
Advisory Directory: http://openpkg.com/go/OpenPKG-SA
Advisory Document: http://openpkg.com/go/OpenPKG-SA-2006.014
Advisory Published: 2010-09-03 23:35 UTC
Issue Id (internal): OpenPKG-SI-20060725.01
Issue First Created: 2006-07-25
Issue Last Modified: 2006-12-07
Issue Revision: 06
Subject Name: OSSP shiela
Subject Summary: Access Control and Logging Facility for CVS Repositories
Subject Home: http://www.ossp.org/pkg/tool/shiela/
Subject Versions: * <= 1.1.6
Vulnerability Id: CVE-2006-3633
Vulnerability Scope: global (not OpenPKG specific)
Attack Feasibility: run-time
Attack Vector: remote network
Attack Impact: arbitrary code execution
Description:
Brian Caswell from Sourcefire discovered [0] vulnerabilities in OSSP
Shiela [1], a CVS repository access control and logging extension.
The vulnerabilities allow arbitrary code execution during CVS file
commits if a filename is specially crafted to contain shell commands.
Notice: OSSP shiela might be installed as a _copy_ into your CVSROOT
area. If this is the case please do not forget to update this copy
after updating the OpenPKG "shiela" package.
References:
[0] http://www.sourcefire.com/services/advisories.html
[1] http://www.ossp.org/pkg/tool/shiela/
Primary Package Name: shiela
Primary Package Home: http://openpkg.org/go/package/shiela
Affected Distribution: Affected Branch: Affected Package:
OpenPKG Community 2.5-SOLID shiela-1.1.6-2.5.0
OpenPKG Community CURRENT shiela-1.1.6-20051003
Corrected Distribution: Corrected Branch: Corrected Package:
OpenPKG Community 2.5-SOLID shiela-1.1.6-2.5.1
OpenPKG Community CURRENT shiela-1.1.7-20060725