Lucene search

K
osvGoogleOSV:DLA-136-1
HistoryJan 24, 2015 - 12:00 a.m.

websvn - security update

2015-01-2400:00:00
Google
osv.dev
8

0.002 Low

EPSS

Percentile

54.7%

James Clawson discovered that websvn, a web viewer for Subversion
repositories, would follow symlinks in a repository when presenting a
file for download. An attacker with repository write access could
thereby access any file on disk readable by the user the webserver
runs as.

For Debian 6 Squeeze, these issues have been fixed in websvn version 2.3.3-1+deb6u1

CPENameOperatorVersion
websvneq2.3.1-1

0.002 Low

EPSS

Percentile

54.7%