HZGN.COM
welcome to my space
X
Welcome to:hzgn.com
Search:  
NAVIGATION: Home >>

'Critical' CVS Heap Overflow Flaw Patched

Published by: wktd 2008-11-20

Security researchers have discovered a heap overflow vulnerability in Concurrent Versions System (CVS), the source code maintenance system used to power open-source software development projects.

An alert from the U.S. Computer Emergency Response Team (US-CERT) said the flaw could allow a remote attacker to launch malicious code on a vulnerable system. Secunia has tagged the vulnerability with a "highly critical" rating.

The heap memory problem was found in the way CVS handles the insertion of modified and unchanged flags within entry lines. When processing an entry line, an additional byte of memory is allocated to flag the entry as modified or unchanged but a failure to check if a byte has been previously allocated for the flag creates an off-by-one buffer overflow, US-CERT said.

"By calling a vulnerable function several times and inserting specific characters into the entry lines, a remote attacker could overwrite multiple blocks of memory. In some environments, the CVS server process is started by the Internet services daemon (inetd) and may run with root privileges," the Center warned.

It effectively means an authenticated client could exploit this vulnerability to execute arbitrary code, execute commands, modify sensitive information, or cause a denial-of-service attack (define).

A new Firefox buffer overflow [LWN.net]::
Reported: September 4, 2005 Severity: Critical Vendor: Mozilla Versions Fedora patched FF and Mozilla too. Thunderbird
http://lwn.net/Articles/150999
HOME
FreeBSD VuXML - entry date index::
hellman handshake flaw. 2005-08-16 quake2 -- multiple critical vulnerabilities cvs pserver remote heap buffer overflow. neon date parsing vulnerability
http://www.vuxml.org/freebsd/index.html
HOME

US-CERT also warned than an anonymous user with read-only access could also exploit a vulnerable server as they are authenticated through the cvspserver process. "In addition to compromising the system running CVS, there is a significant secondary impact in that source code maintained in CVS repositories could be modified to include Trojan horses, backdoors, or other malicious code.

The flaw has been fixed in upgraded CVS versions 1.12.8 and 1.11.16.




Oracle Exec Takes Eclipse Helm
A New Cocoon from Apache

PRINT Add to favorites
#If you have any other info about this subject , Please add it free.#
Your name:
E-mail:
Telphone:

Your comments:


If you have any other info about 'Critical' CVS Heap Overflow Flaw Patched , Please add it free.
  • tower lightning last night
  • may 25 kansas severe weather
  • great flood of 1993
  • doswell s tri state paper when
  • vortex ii
  • amazing hurricane images
  • local on the 8 s come to direct tv
  • australian severe weather season starts active
  • svr warning for high flood risk
  • aerial footage of a waterspout tornado
  • oklahoma august 17 1994
  • historical papers on tornadoes
  • walgreen s will display warnings on their billboards
  •  
  • discover channel tornado special tonight
  • photography of distant lightning with a zoom lens
  • this cant be good ike chasers
  • lightning with recoil leaders
  • wxchallenge now accepting alumni
  • thunderstorm team mesonet the first italian mesonet
  • a capstone study in severe nocturnal llj convection
  • peculiar wave action associated with waterspout moving onshore
  • historic rainfall in the lubbock area
  • september 14 2008 high wind event in kentucky
  • certain death warnings
  • approach of the second season
  • chasing here in nc opinions 14 photos
  • north up or track up
  •  Homepage | Add to favorites | Contact us | Exchange links | LOGIN | Site map | 
    Copyright© 2008 hzgn.com        Site made:CFZ