CVS pserver CVSROOT Passwd File Arbitrary Code Execution

high Nessus Network Monitor Plugin ID 1181

Synopsis

An attacker may execute arbitrary commands on the remote system.

Description

The remote CVS server, according to its version number, might allow an attacker to execute arbitrary commands on the remote system as cvs does not drop root privileges properly.

Solution

Upgrade to most recent version of CVS.

See Also

http://www.nessus.org/u?b3bb9c46

Plugin Details

Severity: High

ID: 1181

Family: Generic

Published: 8/20/2004

Updated: 3/6/2019

Nessus ID: 11970

Reference Information

BID: 9306