Security Advisory cvs security update

Advisory: RHSA-2003:013-11
Type: Security Advisory
Severity: Critical
Issued on: 2003-02-06
Last updated on: 2003-02-05
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
CVEs (cve.mitre.org): CVE-2003-0015

Details

Updated CVS packages are now available for Red Hat Linux Advanced Server.
These updates fix a vulnerability which would permit arbitrary command
execution on servers configured to allow anonymous read-only access.

[Updated 06 Feb 2003]
Added fixed packages for Advanced Workstation 2.1

CVS is a version control system frequently used to manage source code
repositories. During an audit of the CVS sources, Stefan Esser discovered
an exploitable double-free bug in the CVS server.

On servers which are configured to allow anonymous read-only access, this
bug could be used by anonymous users to gain write privileges. Users with
CVS write privileges can then use the Update-prog and Checkin-prog features
to execute arbitrary commands on the server.

All users of CVS are advised to upgrade to these packages which
contain patches to correct the double-free bug.

Our thanks go to Stefan Esser of e-matters for reporting this issue to us.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

This update is available via Red Hat Network. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
cvs-1.11.1p1-8.7.src.rpm
File outdated by:  RHSA-2005:756
    MD5: 960b96371d348764c8a284ceeb439142
 
IA-32:
cvs-1.11.1p1-8.7.i386.rpm
File outdated by:  RHSA-2005:756
    MD5: 9b900d255ad7d445c79e612991c6dba6
 
IA-64:
cvs-1.11.1p1-8.7.ia64.rpm
File outdated by:  RHSA-2005:756
    MD5: 6efda391465869fae84d670303f819ab
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
cvs-1.11.1p1-8.7.src.rpm
File outdated by:  RHSA-2005:756
    MD5: 960b96371d348764c8a284ceeb439142
 
IA-64:
cvs-1.11.1p1-8.7.ia64.rpm
File outdated by:  RHSA-2005:756
    MD5: 6efda391465869fae84d670303f819ab
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

82014 - cvs remote security issue


References


Keywords

cvs, double-free


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/