Overview
Debian Concurrent Versions System (CVS) remote repositories using "pserver" with the cvs-repouid Debian patch are vulnerable to authentication bypass.
Description
CVS is a version control and source code maintenance system that is widely used by open-source software development projects. The "pserver" is one method used to provide remote access to CVS repositories. Debian included a patch/enhancement, referred to as the cvs-repouid patch, to enhance security when using the "pserver" remote access method. |
Impact
Attackers could obtain unauthorized remote access to a CVS repository and modify its contents. |
Solution
Apply the patch |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Debian credits Maks Polunin and Alberto Garcia with independently discovering this issue. This vulnerability was reported in Debian advisory DSA-715-1.
This document was written by Robert Mead based on information from Debian.
Other Information
CVE IDs: | CVE-2004-1342 |
Severity Metric: | 10.55 |
Date Public: | 2005-04-27 |
Date First Published: | 2005-05-05 |
Date Last Updated: | 2005-05-11 14:27 UTC |
Document Revision: | 20 |