Description
The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committers to modify or create Trojan horse programs with the Checkin.prog or Update.prog names, then performing a CVS commit action.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2000-0676 | The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committers to modify or create Trojan horse programs with the Checkin.prog or Update.prog names, then performing a CVS commit action. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T05:28:40.711Z
Reserved: 2000-09-19T00:00:00.000Z
Link: CVE-2000-0680
No data.
Status : Modified
Published: 2000-10-20T04:00:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2000-0680
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD