Overview
Debian Concurrent Versions System (CVS) remote repositories using "pserver" with the cvs-repouid Debian patch are vulnerable to authentication bypass.
Description
CVS is a version control and source code maintenance system that is widely used by open-source software development projects. The "pserver" is one method used to provide remote access to CVS repositories. Debian included a patch/enhancement, referred to as the cvs-repouid patch, to enhance security when using the "pserver" remote access method. |
Impact
Attackers could obtain unauthorized remote access to a CVS repository and modify its contents. |
Solution
Apply the patch |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental |
References
Acknowledgements
Debian credits Maks Polunin and Alberto Garcia with independently discovering this issue. This vulnerability was reported in Debian advisory DSA-715-1.
This document was written by Robert Mead based on information from Debian.
Other Information
| CVE IDs: | CVE-2004-1342 |
| Severity Metric: | 10.55 |
| Date Public: | 2005-04-27 |
| Date First Published: | 2005-05-05 |
| Date Last Updated: | 2005-05-11 14:27 UTC |
| Document Revision: | 20 |