Lucene search

K
cveRedhatCVE-2012-3357
HistoryJul 22, 2012 - 4:55 p.m.

CVE-2012-3357

2012-07-2216:55:39
CWE-200
redhat
web.nvd.nist.gov
40
cve-2012-3357
viewvc
svn
sensitive information
log msg leak
remote attackers

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.006

Percentile

79.3%

The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is copied from an unreadable path, which allows remote attackers to obtain sensitive information, related to a “log msg leak.”

Affected configurations

Nvd
Node
viewvcviewvcRange1.1.14
OR
viewvcviewvcMatch0.8
OR
viewvcviewvcMatch0.9
OR
viewvcviewvcMatch0.9.1
OR
viewvcviewvcMatch0.9.2
OR
viewvcviewvcMatch0.9.3
OR
viewvcviewvcMatch0.9.4
OR
viewvcviewvcMatch1.0.0
OR
viewvcviewvcMatch1.0.1
OR
viewvcviewvcMatch1.0.2
OR
viewvcviewvcMatch1.0.3
OR
viewvcviewvcMatch1.0.4
OR
viewvcviewvcMatch1.0.5
OR
viewvcviewvcMatch1.0.6
OR
viewvcviewvcMatch1.0.7
OR
viewvcviewvcMatch1.0.8
OR
viewvcviewvcMatch1.0.9
OR
viewvcviewvcMatch1.0.10
OR
viewvcviewvcMatch1.0.11
OR
viewvcviewvcMatch1.1.0
OR
viewvcviewvcMatch1.1.1
OR
viewvcviewvcMatch1.1.2
OR
viewvcviewvcMatch1.1.3
OR
viewvcviewvcMatch1.1.4
OR
viewvcviewvcMatch1.1.5
OR
viewvcviewvcMatch1.1.6
OR
viewvcviewvcMatch1.1.7
OR
viewvcviewvcMatch1.1.8
OR
viewvcviewvcMatch1.1.9
OR
viewvcviewvcMatch1.1.10
OR
viewvcviewvcMatch1.1.11
OR
viewvcviewvcMatch1.1.12
OR
viewvcviewvcMatch1.1.13
VendorProductVersionCPE
viewvcviewvc*cpe:2.3:a:viewvc:viewvc:*:*:*:*:*:*:*:*
viewvcviewvc0.8cpe:2.3:a:viewvc:viewvc:0.8:*:*:*:*:*:*:*
viewvcviewvc0.9cpe:2.3:a:viewvc:viewvc:0.9:*:*:*:*:*:*:*
viewvcviewvc0.9.1cpe:2.3:a:viewvc:viewvc:0.9.1:*:*:*:*:*:*:*
viewvcviewvc0.9.2cpe:2.3:a:viewvc:viewvc:0.9.2:*:*:*:*:*:*:*
viewvcviewvc0.9.3cpe:2.3:a:viewvc:viewvc:0.9.3:*:*:*:*:*:*:*
viewvcviewvc0.9.4cpe:2.3:a:viewvc:viewvc:0.9.4:*:*:*:*:*:*:*
viewvcviewvc1.0.0cpe:2.3:a:viewvc:viewvc:1.0.0:*:*:*:*:*:*:*
viewvcviewvc1.0.1cpe:2.3:a:viewvc:viewvc:1.0.1:*:*:*:*:*:*:*
viewvcviewvc1.0.2cpe:2.3:a:viewvc:viewvc:1.0.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 331

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.006

Percentile

79.3%