Walt Mankowski on 28 May 2004 13:47:02 -0000


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] Urgent! Check This Out! CVS is vulnerable.


On Fri, May 28, 2004 at 07:24:21AM -0400, Jeff Abrahamson wrote:
> The post on packetstorm to which cvs links
> 
>     http://www.packetstormsecurity.org/0405-exploits/cvs_linux_freebsd_HEAP.c
> 
> seems less than professional, so my first thought was that it was not
> legitimate.  But poking about it appears not only legit but also that
> the problem was fixed nine days ago.

Debian's cvs package was patched on May 18 to fix this problem, so if
you're running Debian and checking regularly for security updates,
chances are you're fine.

Walt

Attachment: signature.asc
Description: Digital signature