More flaws foul security of open-source repository
Takeaway: Six more security flaws are found in the popular program for maintaining code under development.
Stay on top of the latest tech news with our free IT News Digest e-newsletter, delivered each weekday. Automatically sign up today!By
Robert Lemos
CNET News.com
Security researchers have found at least six more flaws in the open-software world's most popular program for maintaining code under development.
According to a representative of the project that oversees the program, known as the Concurrent Versions System, the vulnerabilities include a flaw that could let an attacker take control of a CVS server from the Internet, putting the code repository's contents at risk. The flaws were discovered as part of an analysis of the program's code following the announcement last month of
The security flaws underscore the advice of
"We have always said that CVS is not secure," he said. "We have never made any quibbles about that."
Major open-source projects, including the Apache Foundation's Apache Web server and the GNOME and KDE Linux desktops, use the Concurrent Versions System to manage code under development. The software allows programmers to check in changed code, and it tracks the different versions of a program under development.
The major projects using the program were notified of the issues May 28. On Wednesday, the security holes were publicly announced.
The majority of the issues were found by two researchers who vetted the source code after the patch for previous flaws was released in May. One of the researchers, Stefan Esser, also found the previous security holes. The issue became even more serious when an online vandal apparently used the former vulnerabilities to gain access to the CVS Project's server and send an e-mail that said he had gained access. The project has retired that server and plans to analyze its files for evidence of the attack, Price said.
The project has already issued a software update to patch the issue, as has Linux seller SuSE. Other Linux distributions that include the software are expected to release updates this week.
SponsoredWhite Papers, Webcasts, and Downloads
- Anthony & Sylvan Pools Takes the Plunge with VoIP ShoreTel
- Oracle iSeminar: Make Compliance Work for You Oracle
- Choosing the Best CRM for Your Organization Oracle
- Oracle Business Brief: Make Compliance Work for You Oracle
- Unified Communications Pocket Guide ShoreTel
Article Categories
- Security
- Security Solutions, IT Locksmith
- Networking and Communications
- E-mail Administration NetNote, Cisco Routers and Switches
- CIO and IT Management
- Project Management, CIO Issues, Strategies that Scale
- Desktops, Laptops & OS
- Windows 2000 Professional, Microsoft Word, Microsoft Excel, Microsoft Access, Windows XP,
- Data Management
- Oracle, SQL Server
- Servers
- Windows NT, Linux NetNote, Windows Server 2003
- Career Development
- Geek Trivia
- Software/Web Development
- Web Development Zone, Visual Basic, .NET
