New UNIX CVS Exploit circulating
The Internet Storm Center is reporting that the cvs exploit published on May 20th has seen used multiple times. PATCH NOW!. The cvs main homepage (cvshome.org) appears to be down. However, you should still be able to obtain patches from mirrors.
New UNIX CVS Exploit circulating
http://www.incidents.org/diary.php?date=2004-05-21
http://isc.sans.org/diary.php?date=2004-05-19
We have received information that exploit code has been has been reported by K-OTik Security. This exploit is a particular concern to Unix admins and could be used to compromise a number of open source projects. It is recommended that you verify signatures. This exploit can affect your system even if you don't run CVS Server. Just using software that is maintained using a compromised server will put your system at risk. One of the Handler's will be setting up a test server this afternoon to confirm that the code works. Stay tuned for more information.
Gentoo update for CVS
http://secunia.com/advisories/11674/
Open BSD
http://secunia.com/advisories/11677/