Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-3357
HistoryJul 22, 2012 - 12:00 a.m.

CVE-2012-3357

2012-07-2200:00:00
ubuntu.com
ubuntu.com
12

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.006

Percentile

79.3%

The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15
does not properly handle log messages when a readable path is copied from
an unreadable path, which allows remote attackers to obtain sensitive
information, related to a “log msg leak.”

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchviewvc< 1.1.5-1.1+squeeze2build0.12.04.1UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.006

Percentile

79.3%