| Vulnerability Name: | CVE-2008-1292 (CCN-40946) | ||||||||
| Assigned: | 2008-02-28 | ||||||||
| Published: | 2008-02-28 | ||||||||
| Updated: | 2009-08-20 | ||||||||
| Summary: | ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtain sensitive information by reading (1) forbidden pathnames in the revision view, (2) log history that can only be reached by traversing a forbidden object, or (3) forbidden diff view path parameters. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-200 | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: CONFIRM Type: UNKNOWN http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=471380 Source: CONFIRM Type: UNKNOWN http://bugs.gentoo.org/show_bug.cgi?id=212288 Source: MITRE Type: CNA CVE-2008-1292 Source: CCN Type: SA29176 ViewVC Multiple Security Issues Source: SECUNIA Type: Vendor Advisory 29176 Source: SECUNIA Type: Vendor Advisory 29460 Source: GENTOO Type: UNKNOWN GLSA-200803-29 Source: CCN Type: ViewVC Changelog Version 1.0.5 (released 28-Feb-2008) Source: CONFIRM Type: UNKNOWN http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?rev=HEAD Source: CCN Type: GLSA-200803-29 ViewVC: Multiple vulnerabilities Source: CCN Type: OSVDB ID: 43042 ViewVC Revision View Restricted Content Disclosure Source: CCN Type: OSVDB ID: 43043 ViewVC Log History Restricted Content Disclosure Source: CCN Type: OSVDB ID: 43044 ViewVC Diff View Restricted Content Disclosure Source: BID Type: Patch 28055 Source: CCN Type: BID-28055 ViewVC Multiple Remote Information Disclosure Vulnerabilities Source: CCN Type: ViewVC Web site ViewVC: Repository Browsing Source: VUPEN Type: UNKNOWN ADV-2008-0734 Source: XF Type: UNKNOWN viewvc-revision-information-disclosure(40946) Source: SUSE Type: SUSE-SA:2008:039 net-snmp security problems | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| Oval Definitions | |||||||||
| |||||||||
| BACK | |||||||||