CVE-2007-2448
Summary
| CVE | CVE-2007-2448 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-06-14 23:30:00 UTC |
| Updated | 2012-11-06 03:38:00 UTC |
| Description | Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Subversion | Subversion | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail - OVH | VUPEN | www.vupen.com | |
| Ubuntu update for subversion - Advisories - Community | SECUNIA | secunia.com | |
| issues.rpath.com/browse/RPL-1896 | CONFIRM | issues.rpath.com | |
| USN-1053-1: Subversion vulnerabilities | Ubuntu | UBUNTU | www.ubuntu.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Subversion Remote Revision Property Information Disclosure Vulnerability | BID | www.securityfocus.com | Patch |
| 36070 | OSVDB | osvdb.org | |
| SecurityTracker.com Archives - Subversion Discloses Potentially Sensitive Revision Properties to Remote Authenticated Users in Certain Cases | SECTRACK | securitytracker.com | Patch |
| subversion.tigris.org/security/CVE-2007-2448-advisory.txt | CONFIRM | subversion.tigris.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2007-06-26 | Mark J Cox | Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2007-2448 The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. |
There are currently no legacy QID mappings associated with this CVE.