Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.50590
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDKSA-2004:108 (cvs)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to cvs
announced via advisory MDKSA-2004:108.

iDEFENSE discovered a flaw in CVS versions prior to 1.1.17 in an
undocumented switch implemented in CVS' history command. The -X
switch specifies the name of the history file which allows an attacker
to determine whether arbitrary system files and directories exist and
whether or not the CVS process has access to them.

This flaw has been fixed in CVS version 1.1.17.

Affected versions: 10.0, 9.2, Corporate Server 2.1

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

https://secure1.securityspace.com/smysecure/catid.html?in=MDKSA-2004:108
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0778
http://www.idefense.com/application/poi/display?id=130&type=vulnerabilities

Risk factor : Medium

CVSS Score:
5.0

Cross-Ref: BugTraq ID: 10955
Common Vulnerability Exposure (CVE) ID: CVE-2004-0778
http://www.securityfocus.com/bid/10955
CERT/CC vulnerability note: VU#579225
http://www.kb.cert.org/vuls/id/579225
http://www.idefense.com/application/poi/display?id=130&type=vulnerabilities
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:108
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10688
XForce ISS Database: cvs-history-info-disclosure(17001)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17001
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.