[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2563-1 viewvc -- several

ID: oval:org.secpod.oval:def:600903Date: (C)2012-10-26   (M)2023-11-09
Class: PATCHFamily: unix




Several vulnerabilities were found in ViewVC, a web interface for CVS and Subversion repositories. CVE-2009-5024: remote attackers can bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attacks via the limit parameter. CVE-2012-3356: the remote SVN views functionality does not properly perform authorization, which allows remote attackers to bypass intended access restrictions. CVE-2012-3357: the SVN revision view does not properly handle log messages when a readable path is copied from an unreadable path, which allows remote attackers to obtain sensitive information. CVE-2012-4533: "function name" lines returned by diff are not properly escaped, allowing attackers with commit access to perform cross site scripting.

Platform:
Debian 6.0
Product:
viewvc
Reference:
DSA-2563-1
CVE-2009-5024
CVE-2012-3356
CVE-2012-3357
CVE-2012-4533
CVE    4
CVE-2009-5024
CVE-2012-3357
CVE-2012-3356
CVE-2012-4533
...
CPE    35
cpe:/a:viewvc:viewvc:0.9.1
cpe:/a:viewvc:viewvc:0.9.2
cpe:/a:viewvc:viewvc:0.9.3
cpe:/a:viewvc:viewvc:0.9.4
...

© SecPod Technologies