漏洞信息详情
Subversion Mod_Authz_Svn元数据信息泄露漏洞。
- CNNVD编号:CNNVD-200412-111
- 危害等级: 中危
- CVE编号:
CVE-2004-0749
- 漏洞类型:
访问验证错误
- 发布时间:
2004-12-23
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
subversion - 漏洞来源:
Subversion -
漏洞简介
Subversion 1.0.7及其早期版本的mod_authz_svn模块不能正确限制访问所有不可读路径下的元数据。远程攻击者可以借助(1)svn log -v,(2) svn propget,或者(3) svn blame和其它后续改名命令获取敏感信息。
漏洞公告
The vendor has released versions 1.0.8 and 1.1.0-rc4 addressing this vulnerability.
Gentoo has released an advisory (GLSA 200409-35) and an updated eBuild to address this issue. Gentoo users are advised to issue the following sequence of commands in order to install the updates:
emerge sync
emerge -pv “>=dev-util/subversion-1.0.8”
emerge “>=dev-util/subversion-1.0.8”
RedHat has released an advisory (FEDORA-2004-318) to address this issue in Fedora Core 2. Please see the referenced advisory for more information.
Conectiva Linux has released advisory CLA-2004:883 along with fixes dealing with this issue. Please see the referenced advisory for more information.
Subversion Subversion 1.0
-
SUbversion subversion-1.0.8.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.0.8.tar.gz
Subversion Subversion 1.0.1
-
Conectiva python-subversion-1.0.1-63329U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/python-subversion-1.0.1-63
329U10_1cl.i386.rpm -
Conectiva subversion-1.0.1-63329U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/subversion-1.0.1-63329U10_
1cl.i386.rpm -
Conectiva subversion-devel-1.0.1-63329U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/subversion-devel-1.0.1-633
29U10_1cl.i386.rpm -
Conectiva subversion-doc-1.0.1-63329U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/subversion-doc-1.0.1-63329
U10_1cl.i386.rpm -
Conectiva subversion-server-1.0.1-63329U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/subversion-server-1.0.1-63
329U10_1cl.i386.rpm -
Conectiva subversion-static-1.0.1-63329U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/subversion-static-1.0.1-63
329U10_1cl.i386.rpm -
SUbversion subversion-1.0.8.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.0.8.tar.gz
Subversion Subversion 1.0.2
-
Fedora mod_dav_svn-1.0.8-1.i386.rpmRedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora mod_dav_svn-1.0.8-1.x86_64.rpmRedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora subversion-1.0.8-1.i386.rpmRedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora subversion-1.0.8-1.x86_64.rpmRedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora subversion-debuginfo-1.0.8-1.i386.rpmRedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora subversion-debuginfo-1.0.8-1.x86_64.rpmRedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora subversion-devel-1.0.8-1.i386.rpmRedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora subversion-devel-1.0.8-1.x86_64.rpmRedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora subversion-perl-1.0.8-1.i386.rpmRedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora subversion-perl-1.0.8-1.x86_64.rpmRedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
SUbversion subversion-1.0.8.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.0.8.tar.gz
Subversion Subversion 1.0.3
-
SUbversion subversion-1.0.8.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.0.8.tar.gz
Subversion Subversion 1.0.4
-
SUbversion subversion-1.0.8.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.0.8.tar.gz
Subversion Subversion 1.0.5
-
SUbversion subversion-1.0.8.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.0.8.tar.gz
Subversion Subversion 1.0.6
-
SUbversion subversion-1.0.8.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.0.8.tar.gz
Subversion Subversion 1.0.7
-
SUbversion subversion-1.0.8.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.0.8.tar.gz
Subversion Subversion 1.1 .0-rc2
-
Subversion subversion-1.1.0-rc4.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.1.0-rc4.tar.gz
Subversion Subversion 1.1 .0-rc3
-
Subversion subversion-1.1.0-rc4.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.1.0-rc4.tar.gz
Subversion Subversion 1.1 .0-rc1
-
Subversion subversion-1.1.0-rc4.tar.gz
http://subversion.tigris.org/tarballs/subversion-1.1.0-rc4.tar.gz
参考网址
来源: XF
名称: subversion-information-disclosure(17472)
链接:http://xforce.iss.net/xforce/xfdb/17472
来源: BID
名称: 11243
链接:http://www.securityfocus.com/bid/11243
来源: GENTOO
名称: GLSA-200409-35
链接:http://www.gentoo.org/security/en/glsa/glsa-200409-35.xml
来源: subversion.tigris.org
链接:http://subversion.tigris.org/security/CAN-2004-0749-advisory.txt
来源: FEDORA
名称: FEDORA-2004-318
链接:http://fedoranews.org/updates/FEDORA-2004-318.shtml