Security issue with cvs

Joe Buck jbuck@synopsys.com
Thu Aug 13 15:38:00 GMT 1998


> as might be well known, there is a security problem with
> the read-only CVS access.  The problem is that when someone
> manages to change or replace the CVSROOT/passwd file,
> then he or she can get root.

If I truly have read-only access, then how can I change or replace
CVSROOT/passwd?

(It is a security bug if folks with *write* access can change that
file, and depending on encoding, it may be a bug if I can fetch it).





More information about the Gcc mailing list