[cvsnt] Recent cvs vulnerability.

Jonathan Belson jon-cvsnt at witchspace.com
Mon Jun 14 16:15:17 BST 2004


Hiya


I notice that the cvshome.com recently got hit by a remote exploit, and
I was wondering if cvsnt shared this vulnerability (I looked back through
the mailing list archives but didn't see any references to it).

This site implies that only pserver is affected:

http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0396

but cvshome.com suggests that *any* remote protocol is vulnerable.

My server uses sspi and has pserver disabled - do I have anything to worry
about?

Cheers,

--
Jon





More information about the cvsnt mailing list