Lucene search

K
debianDebianDEBIAN:DLA-136-1:B7A4C
HistoryJan 24, 2015 - 7:18 p.m.

[SECURITY] [DLA 136-1] websvn security update

2015-01-2419:18:22
lists.debian.org
8

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

6.3 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

54.7%

Package : websvn
Version : 2.3.3-1+deb6u1
CVE ID : CVE-2013-6892
Debian Bug : 775682

James Clawson discovered that websvn, a web viewer for Subversion
repositories, would follow symlinks in a repository when presenting a
file for download. An attacker with repository write access could
thereby access any file on disk readable by the user the webserver
runs as.

OSVersionArchitecturePackageVersionFilename
Debian6allwebsvn< 2.3.1-1+deb6u1websvn_2.3.1-1+deb6u1_all.deb
Debian7allwebsvn< 2.3.3-1.1+deb7u1websvn_2.3.3-1.1+deb7u1_all.deb

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

6.3 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

54.7%