Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: CVS/Subversion remote holes - Reporting MS vulnerabilities - SANS Internet Storm Center SANS ISC InfoSec Forums

Participate: Learn more about our honeypot network

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
CVS/Subversion remote holes - Reporting MS vulnerabilities
CVS/Subversion remote vulnerabilities

E-Matters has released information regarding remotely exploitable overflows in the Subversion and CVS version control applications. Both projects have released fixed versions which should be available for most platforms at the time of this writing. Users of these applications are strongly encouraged to update.

The full advisories are available at the following links:


Reporting a Security Vulnerability in a Microsoft Product

Microsoft's Security Response Center posted the following submission guidelines to multiple security mailing lists earlier today:

"The Microsoft Security Response Center investigates all reports of security vulnerabilities sent to us that affect Microsoft products. If you believe you have found a security vulnerability affecting a Microsoft product, we would like to work with you to investigate it.

We are concerned that people might not know the best way to report security vulnerabilities to Microsoft. You can contact the Microsoft Security Response Center to report a vulnerability by emailing directly, or you can submit your report via our web-based vulnerability reporting form located at:


Microsoft Security Response Center"

Cory Altheide
Handler on Duty

42 Posts
May 20th 2004

Sign Up for Free or Log In to start participating in the conversation!