Upstream information
Description
ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtain sensitive information by reading (1) forbidden pathnames in the revision view, (2) log history that can only be reached by traversing a forbidden object, or (3) forbidden diff view path parameters.NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N)
Novell/SUSE information
Novell Bugzilla entry: 370197 SUSE Security Advisories:- SUSE-SA:2008:039, published Fri, 01 Aug 2008 13:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise Desktop 10 SP1 for AMD64 and Intel EM64T SUSE Linux Enterprise Desktop 10 SP1 for x86 SUSE Linux Enterprise Desktop 10 SP2 for AMD64 and Intel EM64T SUSE Linux Enterprise Desktop 10 SP2 for x86 |
| sle10-sp2-sdk.ppc sle10-sp2-sdk.s390x sle10-sp1-sdk.ia64 sle10-sp1-sdk.s390x sle10-sp1-sdk.x86 sled10-sp2.x86-64 sle10-sp2-sdk.x86 sle10-sp1-sdk.ppc sled10-sp2.x86 sle10-sp2-sdk.ia64 sle10-sp2-sdk.x86-64 sled10.x86 sle10-sp1-sdk.x86-64 sled10.x86-64 ZYPP Patch Nr: 5362 |
| SLE SDK 10 SP1 for IBM iSeries and IBM pSeries SLE SDK 10 SP1 for IBM zSeries SLE SDK 10 SP1 for IPF SLE SDK 10 SP1 for X86-64 SLE SDK 10 SP1 for x86 |
| sle10-sp2-sdk.ppc sle10-sp2-sdk.s390x sle10-sp1-sdk.ia64 sle10-sp1-sdk.s390x sle10-sp1-sdk.x86 sled10-sp2.x86-64 sle10-sp2-sdk.x86 sle10-sp1-sdk.ppc sled10-sp2.x86 sle10-sp2-sdk.ia64 sle10-sp2-sdk.x86-64 sled10.x86 sle10-sp1-sdk.x86-64 sled10.x86-64 ZYPP Patch Nr: 5362 |
| openSUSE 10.2 |
| |
| openSUSE 10.3 |
|
