ViewCVS Multiple Information Disclosure Vulnerabilities
BID:11819
Info
ViewCVS Multiple Information Disclosure Vulnerabilities
| Bugtraq ID: | 11819 |
| Class: | Design Error |
| CVE: |
CVE-2004-0915 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2004 12:00AM |
| Updated: | Jul 12 2009 08:07AM |
| Credit: | Discovery is credited to Hajvan Sehic. |
| Vulnerable: |
ViewCVS ViewCVS 0.9.2 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: | |
Discussion
ViewCVS Multiple Information Disclosure Vulnerabilities
ViewCVS is reportedly prone to multiple information disclosure vulnerabilities when repositories are exported to tar archives.
Reportedly, certain configuration directives are not properly honored when creating tar archives for users to download. This allows remote attackers to gain access to potentially sensitive files located in restricted directories. The contents of these files may aid them in further attacks.
This issue is only exploitable if the package is configured to allow tar archive generation. This is enabled by setting the 'tar_archive' configuration directive to '1'.
ViewCVS is reportedly prone to multiple information disclosure vulnerabilities when repositories are exported to tar archives.
Reportedly, certain configuration directives are not properly honored when creating tar archives for users to download. This allows remote attackers to gain access to potentially sensitive files located in restricted directories. The contents of these files may aid them in further attacks.
This issue is only exploitable if the package is configured to allow tar archive generation. This is enabled by setting the 'tar_archive' configuration directive to '1'.
Exploit / POC
ViewCVS Multiple Information Disclosure Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
ViewCVS Multiple Information Disclosure Vulnerabilities
Solution:
Debian has released an advisory (DSA 605-1) and fixes to address this issue. Please see the referenced advisory for links to fixed packages.
Gentoo has released an advisory GLSA 200412-26 to address various issues in ViewCVS. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot ?verbose ">=www-apps/viewcvs-0.9.2_p20041207-r1"
Debian Linux 3.0
Solution:
Debian has released an advisory (DSA 605-1) and fixes to address this issue. Please see the referenced advisory for links to fixed packages.
Gentoo has released an advisory GLSA 200412-26 to address various issues in ViewCVS. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot ?verbose ">=www-apps/viewcvs-0.9.2_p20041207-r1"
Debian Linux 3.0
-
Debian viewcvs_0.9.2-4woody1_all.deb
http://security.debian.org/pool/updates/main/v/viewcvs/viewcvs_0.9.2-4 woody1_all.deb