Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-4325
HistorySep 30, 2008 - 12:00 a.m.

CVE-2008-4325

2008-09-3000:00:00
ubuntu.com
ubuntu.com
7

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

EPSS

0.016

Percentile

87.8%

lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP
request for the Content-Type header in the HTTP response, which allows
remote attackers to cause content to be misinterpreted by the browser via a
content-type parameter that is inconsistent with the requested object.
NOTE: this issue might not be a vulnerability, since it requires attacker
access to the repository that is being viewed.

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

EPSS

0.016

Percentile

87.8%