info-cvs
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

New version of CVS ACL (permissions) patch - security fix


From: Corey Minyard
Subject: New version of CVS ACL (permissions) patch - security fix
Date: Tue, 23 Oct 2001 14:49:14 -0500
User-agent: Mozilla/5.0 (X11; U; Linux ppc; en-US; rv:0.9.5+) Gecko/20011012

I have released a new version of the CVS ACL patch that I maintain to
fix a rather stupid security bug.  It's on my web page
(http://members.home.net/minyard) and it is the "perm13" version.  If\
you use this patch, upgrading is highly recommended.

If you don't know what this patch does, it adds the following to CVS:

* Per-directory access control lists.
* Remote administration (including letting users change their own
 passwords).
* pserver over SSL (called sserver) that encrypts all information
 between the server and client.

Thanks to the person that caught this and told me about it.

-Corey






reply via email to

[Prev in Thread] Current Thread [Next in Thread]