Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 21 Jan 2003 16:38:56 +0100
From:      Stijn Hoop <stijn@win.tue.nl>
To:        Tod McQuillin <devin@spamcop.net>
Cc:        freebsd-security@freebsd.org
Subject:   Re: CVS remote vulnerability
Message-ID:  <20030121153856.GH219@pcwin002.win.tue.nl>
In-Reply-To: <20030122003247.H455@glass.pun-pun.prv>
References:  <20030122001452.O455@glass.pun-pun.prv> <20030121152352.GG219@pcwin002.win.tue.nl> <20030122003247.H455@glass.pun-pun.prv>

next in thread | previous in thread | raw e-mail | index | archive | help

--Z0mFw3+mXTC5ycVe
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Wed, Jan 22, 2003 at 12:34:20AM +0900, Tod McQuillin wrote:
> On Tue, 21 Jan 2003, Stijn Hoop wrote:
> > The advisory claims that 'This does not apply to :pserver: method only',
> > but what other method exists where you don't have to have a shell accou=
nt?
> > In other words, I have a CVS server where people use :ext: with
> > CVS_RSH=3Dssh. How can one compromise this setup without compromising S=
SH?
>=20
> Even though there is a shell account, maybe the shell is set to cvs
> itself.  If so, normally you can't run anything but cvs but if you can
> exploit it then you can get a shell on the cvs server.

OK, thanks for explaining, I didn't think of that possibility.
Fortunately I only have trusted local users.

--Stijn

--=20
What would this sentence be like if it weren't self-referential?

--Z0mFw3+mXTC5ycVe
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (FreeBSD)

iD8DBQE+LWmQY3r/tLQmfWcRAk1JAJ9QAyYT1XLfhOToWdqVfb2MY7alUQCfR/W8
5eCO2lbOqY2xhl9lcrmZu4w=
=1BGK
-----END PGP SIGNATURE-----

--Z0mFw3+mXTC5ycVe--

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20030121153856.GH219>