Open-Source CVS Project Plugs Security Leaks![]() Open-Source CVS Project Plugs Security LeaksSecurity researchers on Tuesday issued a warning for multiple
The most serious of the flaws could allow a remote compromise of
The flaws range from buffer overflows and memory leaks that could lead
Security alerts aggregator Secunia has slapped a "moderately critical"
CVS, also known as the Concurrent Versioning System, implements a
The system is commonly used as a collaboration tool among open-source
The CVS Project described the buffer overflow as "potentially serious"
It also confirmed that the new version fixes several plugged memory
The group also warned that several potential vulnerabilities in the
"The confirmed vulnerability could allow the execution of arbitrary
A complete description of the problem has been published.
"If you were making use of any of the contributed trigger scripts on a
A fix for this bug, however, is incomplete.
"Taint-checking has been enabled in all the contributed Perl scripts
The latest security hiccup comes at a crucial time for the CVS
On the Project home page, the remnants of that attack are still
"The cvshome site is currently being thoroughly cleaned as a direct
"The publication of this code makes all sites running cvs with any
|
|
Best of the Web 1 | Best of the Web 2 | Best of the Web 3 | Best of the Web 4
Worlds Largest Network
Active © 2006; WorldsLargestNetwork.com ; Rights Reserved