From owner-freebsd-bugs Fri May 31 9:40: 6 2002 Delivered-To: freebsd-bugs@hub.freebsd.org Received: from freefall.freebsd.org (freefall.FreeBSD.org [216.136.204.21]) by hub.freebsd.org (Postfix) with ESMTP id E2F6E37B400 for ; Fri, 31 May 2002 09:40:02 -0700 (PDT) Received: (from gnats@localhost) by freefall.freebsd.org (8.11.6/8.11.6) id g4VGe2l48230; Fri, 31 May 2002 09:40:02 -0700 (PDT) (envelope-from gnats) Date: Fri, 31 May 2002 09:40:02 -0700 (PDT) Message-Id: <200205311640.g4VGe2l48230@freefall.freebsd.org> To: freebsd-bugs@FreeBSD.org Cc: From: Makoto Matsushita Subject: Re: bin/38765: CVS Daemon Vulnerability in 1.11.1p1 Reply-To: Makoto Matsushita Sender: owner-freebsd-bugs@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org The following reply was made to PR bin/38765; it has been noted by GNATS. From: Makoto Matsushita To: sysadmin@alexdupre.com Cc: bug-followup@FreeBSD.org Subject: Re: bin/38765: CVS Daemon Vulnerability in 1.11.1p1 Date: Sat, 01 Jun 2002 01:30:51 +0900 sysadmin> Nope, you are right. I thought it was fixed in 1.11.2, as sysadmin> reported by securityfocus sysadmin> (http://online.securityfocus.com/bid/4829/solution/). Ya, this report says other points, my assumption is not correct. shows the correct information. This problem is fixed in src/rcs.c rev 1.252, which is between cvs-1.11.1 and cvs-1.11.2; FreeBSD's cvs has this bug. -- - Makoto `MAR' Matsushita To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-bugs" in the body of the message