Subversion for Windows Remote Directory Traversal Vulnerability
BID:25468
Info
Subversion for Windows Remote Directory Traversal Vulnerability
| Bugtraq ID: | 25468 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3846 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 28 2007 12:00AM |
| Updated: | Sep 04 2007 06:31PM |
| Credit: | Nils Durner and Christian Grothoff, Colorado Research Institute for Security and Privacy are credited with the discovery of this vulnerability. |
| Vulnerable: |
TortoiseSVN TortoiseSVN 1.4.4 TortoiseSVN TortoiseSVN 1.4.3 TortoiseSVN TortoiseSVN 1.4.2 TortoiseSVN TortoiseSVN 1.4.1 TortoiseSVN TortoiseSVN 1.4 TortoiseSVN TortoiseSVN 1.3.5 TortoiseSVN TortoiseSVN 1.2.6 TortoiseSVN TortoiseSVN 1.1.7 Subversion Subversion 1.4.4 Subversion Subversion 1.4.3 Subversion Subversion 1.4.2 Subversion Subversion 1.4.1 Subversion Subversion 1.4 Subversion Subversion 1.3.2 Subversion Subversion 1.3.1 Subversion Subversion 1.3 Subversion Subversion 1.2.3 Subversion Subversion 1.2.1 Subversion Subversion 1.2 Subversion Subversion 1.1.4 Subversion Subversion 1.1.3 Subversion Subversion 1.1.2 Subversion Subversion 1.1.1 Subversion Subversion 1.1 .0-rc4 Subversion Subversion 1.1 .0-rc3 Subversion Subversion 1.1 .0-rc2 Subversion Subversion 1.1 .0-rc1 Subversion Subversion 1.1 Subversion Subversion 1.0.8 Subversion Subversion 1.0.7 Subversion Subversion 1.0.6 Subversion Subversion 1.0.5 Subversion Subversion 1.0.4 Subversion Subversion 1.0.3 Subversion Subversion 1.0.2 Subversion Subversion 1.0.1 Subversion Subversion 1.0 Subversion Subversion 0.27 |
| Not Vulnerable: |
TortoiseSVN TortoiseSVN 1.4.5 Subversion Subversion 1.4.5 |
Discussion
Subversion for Windows Remote Directory Traversal Vulnerability
Subversion is prone to a remote directory-traversal vulnerability because the application fails to properly sanitize user-supplied input.
Successfully exploiting this issue allows attackers to write arbitrary data to arbitrary locations on unsuspecting users' computers.
This issue affects Subversion running on Microsoft Windows and on any other platform where directory-separator characters are '\' or characters other than '/'.
Versions prior to Subversion 1.4.5 are vulnerable.
Subversion is prone to a remote directory-traversal vulnerability because the application fails to properly sanitize user-supplied input.
Successfully exploiting this issue allows attackers to write arbitrary data to arbitrary locations on unsuspecting users' computers.
This issue affects Subversion running on Microsoft Windows and on any other platform where directory-separator characters are '\' or characters other than '/'.
Versions prior to Subversion 1.4.5 are vulnerable.
Exploit / POC
Subversion for Windows Remote Directory Traversal Vulnerability
Attackers exploit this issue by using standard Subversion client utilities.
Attackers exploit this issue by using standard Subversion client utilities.
Solution / Fix
Subversion for Windows Remote Directory Traversal Vulnerability
Solution:
The vendor released Subversion 1.4.5 to address this issue. Please see the references for more information.
Subversion Subversion 0.27
Subversion Subversion 1.0
Subversion Subversion 1.0.1
Subversion Subversion 1.0.2
Subversion Subversion 1.0.3
Subversion Subversion 1.0.4
Subversion Subversion 1.0.5
Subversion Subversion 1.0.6
Subversion Subversion 1.0.7
Subversion Subversion 1.0.8
Subversion Subversion 1.1
Subversion Subversion 1.1 .0-rc2
Subversion Subversion 1.1 .0-rc3
Subversion Subversion 1.1 .0-rc4
Subversion Subversion 1.1 .0-rc1
Subversion Subversion 1.1.1
Subversion Subversion 1.1.2
Subversion Subversion 1.1.3
Subversion Subversion 1.1.4
TortoiseSVN TortoiseSVN 1.1.7
Subversion Subversion 1.2
Subversion Subversion 1.2.1
Subversion Subversion 1.2.3
TortoiseSVN TortoiseSVN 1.2.6
Subversion Subversion 1.3
Subversion Subversion 1.3.1
Subversion Subversion 1.3.2
TortoiseSVN TortoiseSVN 1.3.5
TortoiseSVN TortoiseSVN 1.4
Subversion Subversion 1.4
Subversion Subversion 1.4.1
TortoiseSVN TortoiseSVN 1.4.1
TortoiseSVN TortoiseSVN 1.4.2
Subversion Subversion 1.4.2
Subversion Subversion 1.4.3
TortoiseSVN TortoiseSVN 1.4.3
TortoiseSVN TortoiseSVN 1.4.4
Subversion Subversion 1.4.4
Solution:
The vendor released Subversion 1.4.5 to address this issue. Please see the references for more information.
Subversion Subversion 0.27
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.0
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.0.1
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.0.2
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.0.3
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.0.4
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.0.5
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.0.6
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.0.7
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.0.8
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.1
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.1 .0-rc2
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.1 .0-rc3
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.1 .0-rc4
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.1 .0-rc1
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.1.1
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.1.2
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.1.3
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.1.4
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
TortoiseSVN TortoiseSVN 1.1.7
-
TortoiseSVN TortoiseSVN-1.4.5.10425-win32-svn-1.4.5.msi
http://downloads.sourceforge.net/tortoisesvn/TortoiseSVN-1.4.5.10425-w in32-svn-1.4.5.msi?modtime=1188133405&big_mirror=0
Subversion Subversion 1.2
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.2.1
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.2.3
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
TortoiseSVN TortoiseSVN 1.2.6
-
TortoiseSVN TortoiseSVN-1.4.5.10425-win32-svn-1.4.5.msi
http://downloads.sourceforge.net/tortoisesvn/TortoiseSVN-1.4.5.10425-w in32-svn-1.4.5.msi?modtime=1188133405&big_mirror=0
Subversion Subversion 1.3
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.3.1
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.3.2
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
TortoiseSVN TortoiseSVN 1.3.5
-
TortoiseSVN TortoiseSVN-1.4.5.10425-win32-svn-1.4.5.msi
http://downloads.sourceforge.net/tortoisesvn/TortoiseSVN-1.4.5.10425-w in32-svn-1.4.5.msi?modtime=1188133405&big_mirror=0
TortoiseSVN TortoiseSVN 1.4
-
TortoiseSVN TortoiseSVN-1.4.5.10425-win32-svn-1.4.5.msi
http://downloads.sourceforge.net/tortoisesvn/TortoiseSVN-1.4.5.10425-w in32-svn-1.4.5.msi?modtime=1188133405&big_mirror=0
Subversion Subversion 1.4
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.4.1
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
TortoiseSVN TortoiseSVN 1.4.1
-
TortoiseSVN TortoiseSVN-1.4.5.10425-win32-svn-1.4.5.msi
http://downloads.sourceforge.net/tortoisesvn/TortoiseSVN-1.4.5.10425-w in32-svn-1.4.5.msi?modtime=1188133405&big_mirror=0
TortoiseSVN TortoiseSVN 1.4.2
-
TortoiseSVN TortoiseSVN-1.4.5.10425-win32-svn-1.4.5.msi
http://downloads.sourceforge.net/tortoisesvn/TortoiseSVN-1.4.5.10425-w in32-svn-1.4.5.msi?modtime=1188133405&big_mirror=0
Subversion Subversion 1.4.2
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
Subversion Subversion 1.4.3
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
TortoiseSVN TortoiseSVN 1.4.3
-
TortoiseSVN TortoiseSVN-1.4.5.10425-win32-svn-1.4.5.msi
http://downloads.sourceforge.net/tortoisesvn/TortoiseSVN-1.4.5.10425-w in32-svn-1.4.5.msi?modtime=1188133405&big_mirror=0
TortoiseSVN TortoiseSVN 1.4.4
-
TortoiseSVN TortoiseSVN-1.4.5.10425-win32-svn-1.4.5.msi
http://downloads.sourceforge.net/tortoisesvn/TortoiseSVN-1.4.5.10425-w in32-svn-1.4.5.msi?modtime=1188133405&big_mirror=0
Subversion Subversion 1.4.4
-
Subversion subversion-1.4.5.tar.bz2
http://subversion.tigris.org/downloads/subversion-1.4.5.tar.bz2
References
Subversion for Windows Remote Directory Traversal Vulnerability
References:
References:
- Subversion Homepage (Subversion)
- TortoiseSVN 1.4.5 released (TortoiseSVN)
- TortoiseSVN Home Page (TortoiseSVN)
- Subversion 1.4.5 releaded (Win32 security release) (Subversion)