WebSVN Known Path Access Restriction Security Bypass Vulnerability
BID:33343
Info
WebSVN Known Path Access Restriction Security Bypass Vulnerability
| Bugtraq ID: | 33343 |
| Class: | Unknown |
| CVE: |
CVE-2009-0240 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 19 2009 12:00AM |
| Updated: | Mar 10 2009 08:56PM |
| Credit: | Florian Weimer |
| Vulnerable: |
WebSVN WebSVN 2.0rc4 WebSVN WebSVN 2.0 WebSVN WebSVN 1.7 Gentoo Linux Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: |
WebSVN WebSVN 2.1 |
Discussion
WebSVN Known Path Access Restriction Security Bypass Vulnerability
WebSVN is prone to a security-bypass vulnerability because it fails to properly implement access control mechanisms.
An attacker can exploit this issue to bypass intended security restrictions and gain access to potentially sensitive files.
Versions prior to WebSVN 2.1 are vulnerable.
WebSVN is prone to a security-bypass vulnerability because it fails to properly implement access control mechanisms.
An attacker can exploit this issue to bypass intended security restrictions and gain access to potentially sensitive files.
Versions prior to WebSVN 2.1 are vulnerable.
Exploit / POC
WebSVN Known Path Access Restriction Security Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
WebSVN Known Path Access Restriction Security Bypass Vulnerability
Solution:
The vendor has addressed this issue in WebSVN 2.1. Please see the references for more information.
WebSVN WebSVN 2.0rc4
WebSVN WebSVN 2.0
WebSVN WebSVN 1.7
Solution:
The vendor has addressed this issue in WebSVN 2.1. Please see the references for more information.
WebSVN WebSVN 2.0rc4
-
WebSVN websvn-2.1.0.tar.gz
http://websvn.tigris.org/files/documents/1380/44451/websvn-2.1.0.tar.g z
WebSVN WebSVN 2.0
-
WebSVN websvn-2.1.0.tar.gz
http://websvn.tigris.org/files/documents/1380/44451/websvn-2.1.0.tar.g z
WebSVN WebSVN 1.7
-
WebSVN websvn-2.1.0.tar.gz
http://websvn.tigris.org/files/documents/1380/44451/websvn-2.1.0.tar.g z
References
WebSVN Known Path Access Restriction Security Bypass Vulnerability
References:
References:
- CVE request: WebSVN (Florian Weimer)
- WebSVN Homepage (WebSVN)