oss-sec mailing list archives
Re: CVS and ssh command injection (see CVE-2017-1000117, etc.)
From: Andreas Stieger <astieger () suse com>
Date: Fri, 11 Aug 2017 10:10:18 +0200
On 08/11/2017 01:32 AM, Hank Leininger wrote:
SSH command injection via -o... impacts CVS 1.12.x as well [...] I don't know if these were discussed on a private list prior to publication, and whether that discussion included CVS.
cvs did not come up in the private discussions that I am aware of, thanks for pointing it out. Andreas -- Andreas Stieger <astieger () suse com> Project Manager Security SUSE Linux GmbH, GF: Felix Imendörffer, Jane Smithard, Graham Norton, HRB 21284 (AG Nürnberg)
Current thread:
- CVS and ssh command injection (see CVE-2017-1000117, etc.) Hank Leininger (Aug 10)
- Re: CVS and ssh command injection (see CVE-2017-1000117, etc.) Andreas Stieger (Aug 11)
- Re: CVS and ssh command injection (see CVE-2017-1000117, etc.) Salvatore Bonaccorso (Aug 11)
- Re: CVS and ssh command injection (see CVE-2017-1000117, etc.) Salvatore Bonaccorso (Aug 11)
- Re: CVS and ssh command injection (see CVE-2017-1000117, etc.) Salvatore Bonaccorso (Aug 11)
- Re: CVS and ssh command injection (see CVE-2017-1000117, etc.) Hanno Böck (Aug 20)
- Re: CVS and ssh command injection (see CVE-2017-1000117, etc.) Andreas Stieger (Aug 11)