FYI


This was posted on [EMAIL PROTECTED] today.

Kind regards,

Niels Heinen


-------- Original Message --------
Subject: Help needed with bufferoverflow in cvs
Date: Wed, 20 Feb 2002 08:46:14 +0100 (CET)
From: <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>

Hi all,

it seems that cvs (version 1.10.7 from Debians stable repos) has a
bufferoverflow but I'm but sure if it's exploitable

ls -la /usr/bin/cvs
-rwxr-xr-x    1 root     root       490160 Mar 22  2000 /usr/bin/cvs

no suid bit but it's owned by root

cvs diff -C`perl -e "print 'a' x 300"` tables.sql

Index: tables.sql
===================================================================
RCS file: /opt/CVSROOT/procedit/sql/tables.sql,v
retrieving revision 1.1
diff -u -3 -p
-Caaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa-r1.1
tables.sql
cvs diff: context length specified twice
Segmentation fault (core dumped)

but couldn't it help someone to get access to the system ?

Best regards
Kim

_______________________________________________
Bug-cvs mailing list
[EMAIL PROTECTED]
http://mail.gnu.org/mailman/listinfo/bug-cvs

Reply via email to