Ubuntu security notices
USN-3399-1: cvs vulnerability
USN-3399-1: cvs vulnerability Ubuntu Security Notice USN-3399-1 21st August, 2017 cvs vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary cvs could be made run programs as your login if it opened a specially crafted cvs repository. Software description cvs – Concurrent Versions System Details Hank Leininger discovered that cvs did not properly handle SSHfor remote repositories. A remote attacker could use this toconstruct a cvs repository that when accessed could run arbitrarycode with the privileges of the user. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.04: cvs 2:1.12.13+real-22ubuntu0.1 Ubuntu 16.04 LTS: cvs 2:1.12.13+real-15ubuntu0.1 Ubuntu 14.04 LTS: cvs 2:1.12.13+real-12ubuntu0.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the [ more… ]