CVE-2007-3846: Path Traversal
Directory traversal vulnerability in Subversion before 1.4.5, as used by TortoiseSVN before 1.4.5 and possibly other products, when run on Windows-based systems, allows remote authenticated users to overwrite and create arbitrary files via a ..\ (dot dot backslash) sequence in the filename, as stored in the file repository.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3846?
CVE-2007-3846 has a medium severity level due to its ability to allow remote authenticated users to overwrite and create arbitrary files.
How do I fix CVE-2007-3846?
To fix CVE-2007-3846, upgrade to Subversion version 1.4.5 or later, or TortoiseSVN version 1.4.5 or later.
What systems are affected by CVE-2007-3846?
CVE-2007-3846 affects Windows-based systems using vulnerable versions of Subversion and TortoiseSVN.
Can CVE-2007-3846 be exploited remotely?
Yes, CVE-2007-3846 can be exploited by remote authenticated users through directory traversal techniques.
What are the consequences of exploiting CVE-2007-3846?
Exploiting CVE-2007-3846 can lead to unauthorized file creation and overwriting, potentially compromising system integrity.