Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2013-2117
HistoryAug 09, 2013 - 8:56 p.m.

CVE-2013-2117

2013-08-0920:56:07
Debian Security Bug Tracker
security-tracker.debian.org
11

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.005

Percentile

77.3%

Directory traversal vulnerability in the cgit_parse_readme function in ui-summary.c in cgit before 0.9.2, when a readme file is set to a filesystem path, allows remote attackers to read arbitrary files via a … (dot dot) in the url parameter.

OSVersionArchitecturePackageVersionFilename
Debian12allcgit< 1.2.3+git20221219.50.91f2590+git2.39.1-1cgit_1.2.3+git20221219.50.91f2590+git2.39.1-1_all.deb
Debian11allcgit< 1.2.3+git2.25.1-1cgit_1.2.3+git2.25.1-1_all.deb
Debian999allcgit< 1.2.3+git20221219.50.91f2590+git2.39.1-1cgit_1.2.3+git20221219.50.91f2590+git2.39.1-1_all.deb
Debian13allcgit< 1.2.3+git20221219.50.91f2590+git2.39.1-1cgit_1.2.3+git20221219.50.91f2590+git2.39.1-1_all.deb

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.005

Percentile

77.3%

Related for DEBIANCVE:CVE-2013-2117