Executive Summary
Summary | |
---|---|
Title | viewvc security update |
Informations | |||
---|---|---|---|
Name | DSA-2563 | First vendor Publication | 2012-10-23 |
Vendor | Debian | Last vendor Modification | 2012-10-23 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Several vulnerabilities were found in ViewVC, a web interface for CVS and Subversion repositories. CVE-2009-5024: remote attackers can bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attacks via the limit parameter. CVE-2012-3356: the remote SVN views functionality does not properly perform authorization, which allows remote attackers to bypass intended access restrictions. CVE-2012-3357: the SVN revision view does not properly handle log messages when a readable path is copied from an unreadable path, which allows remote attackers to obtain sensitive information. CVE-2012-4533: "function name" lines returned by diff are not properly escaped, allowing attackers with commit access to perform cross site scripting. For the stable distribution (squeeze), these problems have been fixed in version 1.1.5-1.1+squeeze2. For the testing distribution (wheezy), these problems will be fixed soon. For the unstable distribution (sid), these problems have been fixed in version 1.1.5-1.4. We recommend that you upgrade your viewvc packages. |
Original Source
Url : http://www.debian.org/security/2012/dsa-2563 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
25 % | CWE-399 | Resource Management Errors |
25 % | CWE-287 | Improper Authentication |
25 % | CWE-200 | Information Exposure |
25 % | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:17965 | |||
Oval ID: | oval:org.mitre.oval:def:17965 | ||
Title: | DSA-2563-1 viewvc - several | ||
Description: | Several vulnerabilities were found in ViewVC, a web interface for CVS and Subversion repositories. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2563-1 CVE-2009-5024 CVE-2012-3356 CVE-2012-3357 CVE-2012-4533 | Version: | 7 |
Platform(s): | Debian GNU/Linux 6.0 Debian GNU/kFreeBSD 6.0 | Product(s): | viewvc |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2012-11-06 | Name : Fedora Update for viewvc FEDORA-2012-16673 File : nvt/gb_fedora_2012_16673_viewvc_fc16.nasl |
2012-11-06 | Name : Fedora Update for viewvc FEDORA-2012-16674 File : nvt/gb_fedora_2012_16674_viewvc_fc17.nasl |
2012-10-29 | Name : Debian Security Advisory DSA 2563-1 (viewvc) File : nvt/deb_2563_1.nasl |
2012-08-30 | Name : Fedora Update for viewvc FEDORA-2012-9433 File : nvt/gb_fedora_2012_9433_viewvc_fc17.nasl |
2012-07-16 | Name : Fedora Update for viewvc FEDORA-2012-9371 File : nvt/gb_fedora_2012_9371_viewvc_fc16.nasl |
2011-06-03 | Name : Fedora Update for viewvc FEDORA-2011-7198 File : nvt/gb_fedora_2011_7198_viewvc_fc13.nasl |
2011-06-03 | Name : Fedora Update for viewvc FEDORA-2011-7222 File : nvt/gb_fedora_2011_7222_viewvc_fc14.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
73464 | ViewVC cvsdb row_limit Bypass limit Parameter Remote DoS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2012-363.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : suse_11_3_viewvc-110520.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : suse_11_4_viewvc-110520.nasl - Type : ACT_GATHER_INFO |
2013-04-20 | Name : The remote Mandriva Linux host is missing a security update. File : mandriva_MDVSA-2013-134.nasl - Type : ACT_GATHER_INFO |
2012-11-26 | Name : The remote Fedora host is missing a security update. File : fedora_2012-16646.nasl - Type : ACT_GATHER_INFO |
2012-11-07 | Name : The remote Fedora host is missing a security update. File : fedora_2012-16673.nasl - Type : ACT_GATHER_INFO |
2012-11-07 | Name : The remote Fedora host is missing a security update. File : fedora_2012-16674.nasl - Type : ACT_GATHER_INFO |
2012-10-24 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2563.nasl - Type : ACT_GATHER_INFO |
2012-07-12 | Name : The remote Fedora host is missing a security update. File : fedora_2012-9371.nasl - Type : ACT_GATHER_INFO |
2012-07-12 | Name : The remote Fedora host is missing a security update. File : fedora_2012-9433.nasl - Type : ACT_GATHER_INFO |
2011-05-31 | Name : The remote Fedora host is missing a security update. File : fedora_2011-7185.nasl - Type : ACT_GATHER_INFO |
2011-05-31 | Name : The remote Fedora host is missing a security update. File : fedora_2011-7198.nasl - Type : ACT_GATHER_INFO |
2011-05-31 | Name : The remote Fedora host is missing a security update. File : fedora_2011-7222.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2017-08-29 09:26:22 |
|
2016-08-18 01:05:05 |
|
2016-04-26 21:51:08 |
|
2014-02-17 11:31:25 |
|
2014-02-14 17:24:37 |
|
2014-02-12 13:26:25 |
|
2012-11-20 13:23:34 |
|
2012-11-20 00:21:27 |
|
2012-11-19 13:20:02 |
|