[security issue] cvs is writtable by everyone.

Started by Ducrot Brunoalmost 25 years ago2 messagescomitters
Jump to latest
#1Ducrot Bruno
ducrot@echo.fr

Hello.

I found a mis-configuration on your CVS server.
The passwd file in the CVSROOT is maintened by CVS !

a single:
cvs -z3 -d :pserver:anoncvs@postgresql.org:/home/projects/pgsql/cvsroot co CVSROOT

and anybody can have the passwd file.

As a proof, I have modified the CVSROOT/loginfo and commited back.

--
Ducrot Bruno

#2Bruce Momjian
bruce@momjian.us
In reply to: Ducrot Bruno (#1)
Re: [security issue] cvs is writtable by everyone.

In case you haven't heard, we have reconfigured CVS and changed all the
passwords. Thanks for the info.

Hello.

I found a mis-configuration on your CVS server.
The passwd file in the CVSROOT is maintened by CVS !

a single:
cvs -z3 -d :pserver:anoncvs@postgresql.org:/home/projects/pgsql/cvsroot co CVSROOT

and anybody can have the passwd file.

As a proof, I have modified the CVSROOT/loginfo and commited back.

--
Ducrot Bruno

---------------------------(end of broadcast)---------------------------
TIP 1: subscribe and unsubscribe commands go to majordomo@postgresql.org

-- 
  Bruce Momjian                        |  http://candle.pha.pa.us
  pgman@candle.pha.pa.us               |  (610) 853-3000
  +  If your life is a hard drive,     |  830 Blythe Avenue
  +  Christ can be your backup.        |  Drexel Hill, Pennsylvania 19026