First published: Fri Aug 11 2017(Updated: )
Command injection vulnerability was found in CVS that can be triggered via malicious SSH URLs. References: <a href="http://www.openwall.com/lists/oss-security/2017/08/11/1">http://www.openwall.com/lists/oss-security/2017/08/11/1</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Distrotech Cvs |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1480800 is considered high due to the potential for command injection through malicious SSH URLs.
To fix REDHAT-BUG-1480800, update the CVS package to the latest version that has addressed this vulnerability.
The affected system includes CVS software that processes SSH URLs.
REDHAT-BUG-1480800 is a command injection vulnerability that can be exploited through specially crafted SSH URLs.
To mitigate the risks of REDHAT-BUG-1480800, restrict the use of CVS and monitor for unauthorized access attempts through SSH.