Date: Fri, 28 Jul 2000 17:36:53 -0400 (EDT)
   From: Pavel Roskin <[EMAIL PROTECTED]>

   I hope that there is no immediate danger. Look at serve_update_prog() - it
   checks whether commits are allowed and exits if they are not. It prints a
   strange message though:

   E Flag -u in modules not allowed in readonly mode

   So unless somebody finds other holes, ther is no obvious way to exploit
   CVS/Update.prog without having write access.

But serve_update_prog appears to permit any command which does not
modify the repository.  And cvs update does not modify the repository.

Ian

Reply via email to