CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image Advisories!: Flaw leave door open for Trojan contamination image
Security Hole
By John Leyden

Linux developers were warned yesterday of a potentially devastating flaw affecting Concurrent Versions System (CVS) software widely used by the open source community.

CVS, a version control and collaboration system often used in open-source software development projects, is commonly configured to allow public, anonymous, read-only access via the Internet.

A "double-free" vulnerability1 in the Concurrent Versions System (CVS) server means that such limited public access is enough for a skilled, remote attacker "to execute arbitrary code, alter program operation, read sensitive information, or cause a denial of service", according to an advisory by security clearing house CERT.


Very nasty.

Through this vuln an attacker who is able to compromise a CVS server can contaminate source-code repositories with Trojan code. Fortunately, a scan of the CERT advisory reveals fixes from major Linux disties are already available.

Which is just as well: after a succession of Trojanised software distributions last year the last thing we need is another such incident. ®

1 Double-free vulnerability - when a process tries to deallocate already freed memory heap corruption occurs. Either a system will crash, or if a cracker has crafted malformed data request containing malicious code, this malware might itself into portions of memory where it is subsequently run.



Resources:
Article source: The Register
Advisors CERT
Discovered by Steffan Esser
Posted on Friday, 24 January 2003 @ 12:25:00 UTC by cj (905 reads)
[ Trackback ]
image

"Advisories!: Flaw leave door open for Trojan contamination" | Login/Create an Account | 2 comments | Search
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: Flaw leave door open for Trojan contamination (Score: 1)
by shikehal  on Saturday, 31 May 2008 @ 15:47:57 UTC
(User Info | Send a Message)
Great article, keep up the good work. ----------------------------------------------------
برامج نت [www.bramjnet.com]| free software [www.tt5r.com]| افضل المواقع العربية [top.tt5r.com]| منتدى برامج نت [www.bramjnet.com]| العاب فلاش - العاب بنات [games.bramjnet.com]| برامج [soft.bramjnet.com]| دليل المواقع [dir.bramjnet.com]| عيادة طب [med.bramjnet.com]| الأرشيف [www.bramjnet.com]| برامج مشروحة [www.bramjnet.com]| برامج ترجمة [soft.bramjnet.com]| برامج الفاكس [soft.bramjnet.com]| برامج طباعة [soft.bramjnet.com]| برامج تحرير [soft.bramjnet.com]| برامج التقاط الصور والشاشات [soft.bramjnet.com]| برامج سطح المكتب [soft.bramjnet.com]| برامج البريد الالكتروني [soft.bramjnet.com]| برامج خدمات البريد الاكتروني [soft.bramjnet.com]| برامج القوائم البريدية [soft.bramjnet.com]| برامج ادوات البريد الاكتروني [soft.bramjnet.com]| برامج مكافحة الرسائل المزعجة [soft.bramjnet.com]| برامج الإنترنت [soft.bramjnet.com]



Re: Flaw leave door open for Trojan contamination (Score: 1)
by shikehal  on Saturday, 31 May 2008 @ 15:49:19 UTC
(User Info | Send a Message)
برامج مشاهده القنوات الفضائيه [soft.bramjnet.com]| برامج تسربع الانترنت [soft.bramjnet.com]| برامج تحميل الملفات والصور [soft.bramjnet.com]| برامج المحادثة [soft.bramjnet.com]| برامج ماسنجر [soft.bramjnet.com]| اتصال دولي - الرسائل القصيره [soft.bramjnet.com]| إدوات خدمية وتعاريف قطع جهاز [soft.bramjnet.com]| برامج نسخ الأحتياطي [soft.bramjnet.com]| ادارة الملفات [soft.bramjnet.com]| تقارير الاداء [soft.bramjnet.com]| ضغط وفك ضغط الملفات [soft.bramjnet.com]| الصيانة والمعالجة [soft.bramjnet.com]| ادارة النظام [soft.bramjnet.com]| برامج تحرير الذاكره [soft.bramjnet.com]| الحفظ الاحتياطي [soft.bramjnet.com]| برامج الاداره والتحكم [soft.bramjnet.com]| برامج شبكات [soft.bramjnet.com]| برامج الحماية [soft.bramjnet.com]| برامج مكافحة الفايروسات [soft.bramjnet.com]|Read the rest of this comment...


 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Linux.com
· HotScripts
· W3 Consortium
· More about Security Hole
· News by cj


Most read story about Security Hole:
Windows Media Player, Spyware and Trojan

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer