First published: Tue Aug 28 2007(Updated: )
Directory traversal vulnerability in Subversion before 1.4.5, as used by TortoiseSVN before 1.4.5 and possibly other products, when run on Windows-based systems, allows remote authenticated users to overwrite and create arbitrary files via a ..\ (dot dot backslash) sequence in the filename, as stored in the file repository.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Subversion | <=1.4.4 | |
Exoticpetnetwork Tortoise Forum | <=1.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3846 has a medium severity level due to its ability to allow remote authenticated users to overwrite and create arbitrary files.
To fix CVE-2007-3846, upgrade to Subversion version 1.4.5 or later, or TortoiseSVN version 1.4.5 or later.
CVE-2007-3846 affects Windows-based systems using vulnerable versions of Subversion and TortoiseSVN.
Yes, CVE-2007-3846 can be exploited by remote authenticated users through directory traversal techniques.
Exploiting CVE-2007-3846 can lead to unauthorized file creation and overwriting, potentially compromising system integrity.