CVE-2007-5743: High severity viewvc ViewVC vulnerability
Published Nov 7, 2019
·Updated
viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.
Affected Software
5 affected components
debian/viewvc
viewvc ViewVC=1.0.3
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Event History
Nov 7, 2019
CVE Published
10:15 PM
Nov 8, 2019
CVE Published
via MITRE·02:55 AM
Data Sourced
via MITRE·02:55 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5743?
CVE-2007-5743 is classified as a moderate severity vulnerability due to improper access control.
2
How do I fix CVE-2007-5743?
To fix CVE-2007-5743, ensure that your configuration settings for access control are properly defined and up-to-date.
3
What software versions are affected by CVE-2007-5743?
CVE-2007-5743 affects ViewVC version 1.0.3 and various Debian Linux versions including 8.0, 9.0, and 10.0.
4
What type of vulnerability is CVE-2007-5743?
CVE-2007-5743 is an access control vulnerability that allows unauthorized access to files in a repository.
5
Is there a workaround for CVE-2007-5743?
A possible workaround for CVE-2007-5743 is to review and adjust the forbidden configuration option to restrict file access appropriately.