Updated cvs packages are now available for Red Hat Linux 6.2, 7, 7.1, 7.2,
7.3, and 8.0. These updates close a vulnerability which would permit
arbitrary command execution on servers configured to allow anonymous
read-only access.
[Updated 16 April 2003]
Added packages for Red Hat Linux on IBM iSeries and pSeries systems
CVS is a version control system frequently used to manage source code
repositories. During an audit of the CVS sources, Stefan Esser
discovered an exploitable double-free bug in the CVS server.
On servers which are configured to allow anonymous read-only access, this
bug could be used by anonymous users to gain write privileges. Users with
CVS write privileges can then use the Update-prog and Checkin-prog features
to execute arbitrary commands on the server.
All users of CVS are advised to upgrade to these erratum packages which
contain patches to correct the double-free bug.
Our thanks go to Stefan Esser of e-matters for reporting this issue to us.
| Red Hat Linux 6.2 |
|
| SRPMS: |
ftp://updates.redhat.com/6.2/en/os/SRPMS/cvs-1.11.1p1-8.6.src.rpm
Missing file |
2f93de016c503c5bb057280a5b3c21e3 |
| |
| IA-32: |
ftp://updates.redhat.com/6.2/en/os/i386/cvs-1.11.1p1-8.6.i386.rpm
Missing file |
0009017869564842d5ce5aa99fe71466 |
| |
| Red Hat Linux 7.0 |
|
| SRPMS: |
ftp://updates.redhat.com/7.0/en/os/SRPMS/cvs-1.11.1p1-8.7.src.rpm
Missing file |
960b96371d348764c8a284ceeb439142 |
| |
| IA-32: |
ftp://updates.redhat.com/7.0/en/os/i386/cvs-1.11.1p1-8.7.i386.rpm
Missing file |
9b900d255ad7d445c79e612991c6dba6 |
| |
| Red Hat Linux 7.1 |
|
| SRPMS: |
ftp://updates.redhat.com/7.1/en/os/SRPMS/cvs-1.11.1p1-8.7.src.rpm
Missing file |
960b96371d348764c8a284ceeb439142 |
| |
| IA-32: |
ftp://updates.redhat.com/7.1/en/os/i386/cvs-1.11.1p1-8.7.i386.rpm
Missing file |
9b900d255ad7d445c79e612991c6dba6 |
| |
| Red Hat Linux 7.1 for iSeries |
|
| SRPMS: |
ftp://updates.redhat.com/7.1/en/os/iSeries/SRPMS/cvs-1.11.1p1-8.7.src.rpm
Missing file |
960b96371d348764c8a284ceeb439142 |
| |
| iSeries: |
ftp://updates.redhat.com/7.1/en/os/iSeries/ppc/cvs-1.11.1p1-8.7.ppc.rpm
Missing file |
b1c0aaa488c6508ce0978237feccc2fd |
| |
| Red Hat Linux 7.1 for pSeries |
|
| SRPMS: |
ftp://updates.redhat.com/7.1/en/os/pSeries/SRPMS/cvs-1.11.1p1-8.7.src.rpm
Missing file |
960b96371d348764c8a284ceeb439142 |
| |
| pSeries: |
ftp://updates.redhat.com/7.1/en/os/pSeries/ppc/cvs-1.11.1p1-8.7.ppc.rpm
Missing file |
b1c0aaa488c6508ce0978237feccc2fd |
| |
| Red Hat Linux 7.2 |
|
| SRPMS: |
ftp://updates.redhat.com/7.2/en/os/SRPMS/cvs-1.11.1p1-8.7.src.rpm
Missing file |
960b96371d348764c8a284ceeb439142 |
| |
| IA-32: |
ftp://updates.redhat.com/7.2/en/os/i386/cvs-1.11.1p1-8.7.i386.rpm
Missing file |
9b900d255ad7d445c79e612991c6dba6 |
| |
| IA-64: |
ftp://updates.redhat.com/7.2/en/os/ia64/cvs-1.11.1p1-8.7.ia64.rpm
Missing file |
6efda391465869fae84d670303f819ab |
| |
| Red Hat Linux 7.3 |
|
| SRPMS: |
ftp://updates.redhat.com/7.3/en/os/SRPMS/cvs-1.11.1p1-8.7.src.rpm
Missing file |
960b96371d348764c8a284ceeb439142 |
| |
| IA-32: |
ftp://updates.redhat.com/7.3/en/os/i386/cvs-1.11.1p1-8.7.i386.rpm
Missing file |
9b900d255ad7d445c79e612991c6dba6 |
| |
| Red Hat Linux 8.0 |
|
| SRPMS: |
ftp://updates.redhat.com/8.0/en/os/SRPMS/cvs-1.11.2-8.src.rpm
Missing file |
f1306501984e0a5736d52eb137fd144c |
| |
| IA-32: |
ftp://updates.redhat.com/8.0/en/os/i386/cvs-1.11.2-8.i386.rpm
Missing file |
612a4814740dc8544619a22487b4652f |
| |