HZGN.COM
welcome to my space
X
Search:  
Welcome to:hzgn.com
 HOME   Open Source CVS Flaw Sparks Use Audits
Open Source CVS Flaw Sparks Use Audits
Published by: jack 2008-11-20

9/24: Adware-LesToolbar an Adware Program - Security Camera::
Adware-LesToolbar is not a virus or trojan, but a direct-marketing adware application. This application generates extra pop-up ads while using Internet Explorer.
http://www.100share.com/related/924-AdwareLesToolbar-an-A.htm
HOME
Security researchers have found multiple potential security flaws in one of the main tools of modern open source code management, the Concurrent Version System. However, new versions of CVS have already been issued that correct the flaws.

CVS, a source code maintenance system, has become the standard software configuration management (SCM) system of the Free and Open Source development communities. CVS enables developers to contribute and collaborate on code without version conflicts. It also allows developers to store the current version of the source code as well as a record of all committed changes and who made them.

www.cse.unsw.edu.au/~dons/code/irc-logs/04.12.14::
Plus the open source world functions mostly off of reputation anyway. use gnuplot 03:40:37 <wli> yeah, Ill probably resort to dumping data and using
http://www.cse.unsw.edu.au/~dons/code/irc-logs/04.12.14
HOME
Online Books that are Free Online for you to READ !::
How to Use Microsoft Publisher 98 by Rebecca Reese, Kathy Ivens Open Sources: Voices from the Open Source Revolution published by OReilly & Associates
http://www.infosyssec.org/infosyssec/security/onlinebooks1.htm
HOME
The latest flaw comes after security researchers warned of a flaw in the CVS that could be used to launch malicious code on the vulnerable system. Security researchers released a patch for that "critical" vulnerability late last month.

However, researchers have since found several additional vulnerabilities. One involves a flaw that could lead to a missing NULL terminator; others relate to an error_prog_name string, an argument integer overflow and an out of bounds issue in serv_notify code.

A malicious attacker could theoretically exploit that vulnerability to execute code, execute commands, read sensitive information, or cause a denial of service attack (define). Even an anonymous user with only read-only access could exploit the vulnerability on an un-patched server.

www.cse.unsw.edu.au/~dons/code/irc-logs/04.12.20::
So are you using the Attribute Grammars Use of monads started with list comprehensions. She uses some other open source apps for her translation work.
http://www.cse.unsw.edu.au/~dons/code/irc-logs/04.12.20
HOME
Heritage Policy Weblog Archive::
Lawmakers solution is to restrict the use of shotguns, which are rarely used in many voice chat programs are open-source; these would be difficult or impossible
http://www.heritage.org/Press/DailyBriefing/PolicyWeblog-Archive.cfm?month=7&year=2004
HOME
CVS project maintainers at http://www.cvshome.org have released new versions of CVS, 1.12.9 and 1.11.7, as well as binaries for most major Linux distributions.

The group also recommended that all CVS users upgrade to the latest version. In addition, they said the vulnerabilities relate almost entirely to the pserver method of accessing CVS.

Pserver is a daemon (define) implementation of CVS and was supposed to be a more organized way of using CVS. The pserver read-only access is for general public use and is used to help end users get up to date versions of software. Beyond updating to the latest versions of CVS, the security advisories also said users should consider running their CVS server chrooted over SSH rather than using the pserver daemon.

CVS is the dominant code version management tool in use today by many open source projects, including the Apache Software Foundation, which, according to board member Ken Coar, plans to review its CVS usage.

"Of course time will be spent examining our repositories," Coar told internetnews.com. "I daresay the same will apply to any other group using distributed CVS."

Though CVS dominates in usage with many major open source development projects, another system, known Subversion (SVN), is starting to make itself known. Some in the open source community even see SVN as a successor to CVS, both of which are sponsored by Brian Behlendorf's CollabNet (also of Apache Software Foundation).

But Coar said he doesn't see recent issues with CVS as enough for the Apache Software Foundation to drop CVS and move to SVN. "My personal opinion is that it's unlikely, at least as a consequence of these vulnerabilities," Coar said. "There's a significant overlap of ASF developers with the SVN project, and there has been discussion about moving to SVN, partly because the technology is seen as more robust and current. Some of the ASF projects already use SVN rather than CVS," he said.

"I think that over time new projects will choose their repository tool, and the older projects may or may not migrate. But again, that's not because of any security issues in CVS. These discussions go back many months."




Mozilla's Newest FireFox Takes Flight
Inside Microsoft's Next Big Thing

#If you have any other info about this subject , Please add it free.#
Your name:
E-mail:
Telphone:

Your comments:


If you have any other info about Open Source CVS Flaw Sparks Use Audits , Please add it free.
 Homepage | Add to favorites | Contact us | Exchange links | LOGIN | Site map | 
Copyright© 2008 hzgn.com        Site made:CFZ