cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cvs | Cvs | 1.12.12 (including) | 1.12.12 (including) |
Red Hat Enterprise Linux 3 | RedHat | cvs-0:1.11.2-28 | * |
Red Hat Enterprise Linux 4 | RedHat | cvs-0:1.11.17-8.RHEL4 | * |
Gcvs | Ubuntu | dapper | * |
Gcvs | Ubuntu | devel | * |
Gcvs | Ubuntu | edgy | * |
Gcvs | Ubuntu | feisty | * |