First published: Tue Aug 28 2007(Updated: )
Directory traversal vulnerability in Subversion before 1.4.5, as used by TortoiseSVN before 1.4.5 and possibly other products, when run on Windows-based systems, allows remote authenticated users to overwrite and create arbitrary files via a ..\ (dot dot backslash) sequence in the filename, as stored in the file repository.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Subversion Subversion | <=1.4.4 | |
Tortoisesvn Tortoisesvn | <=1.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.