Subversion Mod_Authz_Svn元数据信息泄露漏洞。

漏洞信息详情

Subversion Mod_Authz_Svn元数据信息泄露漏洞。

漏洞简介

Subversion 1.0.7及其早期版本的mod_authz_svn模块不能正确限制访问所有不可读路径下的元数据。远程攻击者可以借助(1)svn log -v,(2) svn propget,或者(3) svn blame和其它后续改名命令获取敏感信息。

漏洞公告

The vendor has released versions 1.0.8 and 1.1.0-rc4 addressing this vulnerability.
Gentoo has released an advisory (GLSA 200409-35) and an updated eBuild to address this issue. Gentoo users are advised to issue the following sequence of commands in order to install the updates:
emerge sync
emerge -pv “>=dev-util/subversion-1.0.8”
emerge “>=dev-util/subversion-1.0.8”
RedHat has released an advisory (FEDORA-2004-318) to address this issue in Fedora Core 2. Please see the referenced advisory for more information.
Conectiva Linux has released advisory CLA-2004:883 along with fixes dealing with this issue. Please see the referenced advisory for more information.
Subversion Subversion 1.0

Subversion Subversion 1.0.1

Subversion Subversion 1.0.2

Subversion Subversion 1.0.3

Subversion Subversion 1.0.4

Subversion Subversion 1.0.5

Subversion Subversion 1.0.6

Subversion Subversion 1.0.7

Subversion Subversion 1.1 .0-rc2

Subversion Subversion 1.1 .0-rc3

Subversion Subversion 1.1 .0-rc1

参考网址

来源: XF
名称: subversion-information-disclosure(17472)
链接:http://xforce.iss.net/xforce/xfdb/17472

来源: BID
名称: 11243
链接:http://www.securityfocus.com/bid/11243

来源: GENTOO
名称: GLSA-200409-35
链接:http://www.gentoo.org/security/en/glsa/glsa-200409-35.xml

来源: subversion.tigris.org
链接:http://subversion.tigris.org/security/CAN-2004-0749-advisory.txt

来源: FEDORA
名称: FEDORA-2004-318
链接:http://fedoranews.org/updates/FEDORA-2004-318.shtml

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享