Subversion Mod_Authz_Svn Metadata Information Disclosure Vulnerability
BID:11243
Info
Subversion Mod_Authz_Svn Metadata Information Disclosure Vulnerability
| Bugtraq ID: | 11243 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-0749 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | This vulnerability was disclosed by the vendor. |
| Vulnerable: |
Subversion Subversion 1.1 .0-rc3 Subversion Subversion 1.1 .0-rc2 Subversion Subversion 1.1 .0-rc1 Subversion Subversion 1.0.7 Subversion Subversion 1.0.6 Subversion Subversion 1.0.5 Subversion Subversion 1.0.4 Subversion Subversion 1.0.3 Subversion Subversion 1.0.2 Subversion Subversion 1.0.1 Subversion Subversion 1.0 Gentoo Linux 1.4 _rc3 Gentoo Linux 1.4 _rc2 Gentoo Linux 1.4 _rc1 Gentoo Linux 1.4 Gentoo Linux 1.2 Gentoo Linux 1.1 a Gentoo Linux 0.7 Gentoo Linux 0.5 |
| Not Vulnerable: |
Subversion Subversion 1.1 .0-rc4 Subversion Subversion 1.0.8 |
Discussion
Subversion Mod_Authz_Svn Metadata Information Disclosure Vulnerability
It is reported that Subversions mod_authz_svn module is susceptible to an information disclosure vulnerability.
This vulnerability is presents itself when paths that are marked as unreadable are accessed by particular Subversion client commands. It is reportedly possible to disclose the existence of files that are inaccessible to users. Under certain circumstances it may also be possible to disclose commit log messages, or even the contents of files that are configured to be inaccessible to users.
This vulnerability is reported to exist in versions prior to 1.0.8 and 1.1.0-rc4.
It is reported that Subversions mod_authz_svn module is susceptible to an information disclosure vulnerability.
This vulnerability is presents itself when paths that are marked as unreadable are accessed by particular Subversion client commands. It is reportedly possible to disclose the existence of files that are inaccessible to users. Under certain circumstances it may also be possible to disclose commit log messages, or even the contents of files that are configured to be inaccessible to users.
This vulnerability is reported to exist in versions prior to 1.0.8 and 1.1.0-rc4.
Exploit / POC
Subversion Mod_Authz_Svn Metadata Information Disclosure Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Subversion Mod_Authz_Svn Metadata Information Disclosure Vulnerability
Solution:
The vendor has released versions 1.0.8 and 1.1.0-rc4 addressing this vulnerability.
Gentoo has released an advisory (GLSA 200409-35) and an updated eBuild to address this issue. Gentoo users are advised to issue the following sequence of commands in order to install the updates:
emerge sync
emerge -pv ">=dev-util/subversion-1.0.8"
emerge ">=dev-util/subversion-1.0.8"
RedHat has released an advisory (FEDORA-2004-318) to address this issue in Fedora Core 2. Please see the referenced advisory for more information.
Conectiva Linux has released advisory CLA-2004:883 along with fixes dealing with this issue. Please see the referenced advisory for more information.
Subversion Subversion 1.0
Subversion Subversion 1.0.1
Subversion Subversion 1.0.2
Subversion Subversion 1.0.3
Subversion Subversion 1.0.4
Subversion Subversion 1.0.5
Subversion Subversion 1.0.6
Subversion Subversion 1.0.7
Subversion Subversion 1.1 .0-rc2
Subversion Subversion 1.1 .0-rc3
Subversion Subversion 1.1 .0-rc1
Solution:
The vendor has released versions 1.0.8 and 1.1.0-rc4 addressing this vulnerability.
Gentoo has released an advisory (GLSA 200409-35) and an updated eBuild to address this issue. Gentoo users are advised to issue the following sequence of commands in order to install the updates:
emerge sync
emerge -pv ">=dev-util/subversion-1.0.8"
emerge ">=dev-util/subversion-1.0.8"
RedHat has released an advisory (FEDORA-2004-318) to address this issue in Fedora Core 2. Please see the referenced advisory for more information.
Conectiva Linux has released advisory CLA-2004:883 along with fixes dealing with this issue. Please see the referenced advisory for more information.
Subversion Subversion 1.0
-
SUbversion subversion-1.0.8.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.0.8.tar.gz
Subversion Subversion 1.0.1
-
Conectiva python-subversion-1.0.1-63329U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/python-subversion-1.0.1-63 329U10_1cl.i386.rpm -
Conectiva subversion-1.0.1-63329U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/subversion-1.0.1-63329U10_ 1cl.i386.rpm -
Conectiva subversion-devel-1.0.1-63329U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/subversion-devel-1.0.1-633 29U10_1cl.i386.rpm -
Conectiva subversion-doc-1.0.1-63329U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/subversion-doc-1.0.1-63329 U10_1cl.i386.rpm -
Conectiva subversion-server-1.0.1-63329U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/subversion-server-1.0.1-63 329U10_1cl.i386.rpm -
Conectiva subversion-static-1.0.1-63329U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/subversion-static-1.0.1-63 329U10_1cl.i386.rpm -
SUbversion subversion-1.0.8.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.0.8.tar.gz
Subversion Subversion 1.0.2
-
Fedora mod_dav_svn-1.0.8-1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora mod_dav_svn-1.0.8-1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora subversion-1.0.8-1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora subversion-1.0.8-1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora subversion-debuginfo-1.0.8-1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora subversion-debuginfo-1.0.8-1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora subversion-devel-1.0.8-1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora subversion-devel-1.0.8-1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora subversion-perl-1.0.8-1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora subversion-perl-1.0.8-1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
SUbversion subversion-1.0.8.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.0.8.tar.gz
Subversion Subversion 1.0.3
-
SUbversion subversion-1.0.8.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.0.8.tar.gz
Subversion Subversion 1.0.4
-
SUbversion subversion-1.0.8.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.0.8.tar.gz
Subversion Subversion 1.0.5
-
SUbversion subversion-1.0.8.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.0.8.tar.gz
Subversion Subversion 1.0.6
-
SUbversion subversion-1.0.8.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.0.8.tar.gz
Subversion Subversion 1.0.7
-
SUbversion subversion-1.0.8.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.0.8.tar.gz
Subversion Subversion 1.1 .0-rc2
-
Subversion subversion-1.1.0-rc4.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.1.0-rc4.tar.gz
Subversion Subversion 1.1 .0-rc3
-
Subversion subversion-1.1.0-rc4.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.1.0-rc4.tar.gz
Subversion Subversion 1.1 .0-rc1
-
Subversion subversion-1.1.0-rc4.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.1.0-rc4.tar.gz
References
Subversion Mod_Authz_Svn Metadata Information Disclosure Vulnerability
References:
References:
- mod_authz_svn fails to protect metadata (Subversion)
- Subversion Homepage (Subversion)