First published: Thu Sep 21 2000(Updated: )
The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committers to modify or create Trojan horse programs with the Checkin.prog or Update.prog names, then performing a CVS commit action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cvs Cvs | =1.10.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.