CVE-2008-1475
Summary
| CVE | CVE-2008-1475 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-03-24 22:44:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Roundup-tracker | Roundup | 0.1.0 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.1.1 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.1.2 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.1.3 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.2.0 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.2.1 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.2.2 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.2.3 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.2.4 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.2.5 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.2.6 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.2.7 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.2.8 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.3.0 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.3.0 | pre1 | All | All |
| Application | Roundup-tracker | Roundup | 0.3.0 | pre2 | All | All |
| Application | Roundup-tracker | Roundup | 0.3.0 | pre3 | All | All |
| Application | Roundup-tracker | Roundup | 0.4.0 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.4.0 | b1 | All | All |
| Application | Roundup-tracker | Roundup | 0.4.0 | b2 | All | All |
| Application | Roundup-tracker | Roundup | 0.4.1 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.4.2 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.4.2 | pr1 | All | All |
| Application | Roundup-tracker | Roundup | 0.5 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.5.0 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.5.0 | beta1 | All | All |
| Application | Roundup-tracker | Roundup | 0.5.0 | beta2 | All | All |
| Application | Roundup-tracker | Roundup | 0.5.0 | pr1 | All | All |
| Application | Roundup-tracker | Roundup | 0.5.1 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.5.2 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.5.3 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.5.4 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.5.5 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.5.6 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.5.7 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.5.8 | stable | All | All |
| Application | Roundup-tracker | Roundup | 0.5.9 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.6.0 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.6.0 | b1 | All | All |
| Application | Roundup-tracker | Roundup | 0.6.0 | b2 | All | All |
| Application | Roundup-tracker | Roundup | 0.6.0 | b3 | All | All |
| Application | Roundup-tracker | Roundup | 0.6.0 | b4 | All | All |
| Application | Roundup-tracker | Roundup | 0.6.1 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.6.10 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.6.11 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.6.2 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.6.3 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.6.4 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.6.5 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.6.6 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.6.7 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.6.8 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.6.9 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.7.0 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.7.0 | b1 | All | All |
| Application | Roundup-tracker | Roundup | 0.7.0 | b2 | All | All |
| Application | Roundup-tracker | Roundup | 0.7.0 | b3 | All | All |
| Application | Roundup-tracker | Roundup | 0.7.1 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.7.10 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.7.11 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.7.12 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.7.2 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.7.3 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.7.4 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.7.5 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.7.6 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.7.7 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.7.8 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.7.9 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.8.0 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.8.0 | b1 | All | All |
| Application | Roundup-tracker | Roundup | 0.8.0 | b2 | All | All |
| Application | Roundup-tracker | Roundup | 0.8.1 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.8.2 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.8.3 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.8.4 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.8.5 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.8.6 | All | All | All |
| Application | Roundup-tracker | Roundup | 0.9.0 | b1 | All | All |
| Application | Roundup-tracker | Roundup | 1.0 | All | All | All |
| Application | Roundup-tracker | Roundup | 1.0.1 | All | All | All |
| Application | Roundup-tracker | Roundup | 1.1.0 | All | All | All |
| Application | Roundup-tracker | Roundup | 1.1.1 | All | All | All |
| Application | Roundup-tracker | Roundup | 1.1.2 | All | All | All |
| Application | Roundup-tracker | Roundup | 1.2.0 | All | All | All |
| Application | Roundup-tracker | Roundup | 1.2.1 | All | All | All |
| Application | Roundup-tracker | Roundup | 1.3.0 | All | All | All |
| Application | Roundup-tracker | Roundup | 1.3.1 | All | All | All |
| Application | Roundup-tracker | Roundup | 1.3.2 | All | All | All |
| Application | Roundup-tracker | Roundup | 1.3.3 | All | All | All |
| Application | Roundup-tracker | Roundup | 1.4.0 | All | All | All |
| Application | Roundup-tracker | Roundup | 1.4.1 | All | All | All |
| Application | Roundup-tracker | Roundup | 1.4.2 | All | All | All |
| Application | Roundup-tracker | Roundup | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Roundup: Permission bypass — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| 436546 – (CVE-2008-1474) CVE-2008-1474 Roundup 1.4.4 contains security fixes | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| [SECURITY] Fedora 7 Update: roundup-1.4.4-1.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| [SECURITY] Fedora 8 Update: roundup-1.4.4-1.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Fedora update for roundup - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail | OVH- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Fedora update for roundup - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Roundup Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Roundup XML-RPC Server Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| [SECURITY] Fedora 8 Update: roundup-1.4.6-1.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Page not found - SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| [SECURITY] Fedora 9 Update: roundup-1.4.6-1.fc9 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Gentoo update for roundup - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.