CVE-2008-1290: Infoleak
Published Mar 24, 2008
·Updated
ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote attackers to obtain sensitive information.
Affected Software
5 affected components
Gentoo Linux
redhat Fedora=7
redhat Fedora=8
viewvc ViewVC=1.0.2
viewvc ViewVC=1.0.3
Remediation
Patch Available
Event History
Mar 24, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
05:44 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-1290?
CVE-2008-1290 has a medium severity rating as it allows remote attackers to obtain sensitive information.
2
How do I fix CVE-2008-1290?
To fix CVE-2008-1290, upgrade ViewVC to a version later than 1.0.5.
3
What affected versions of ViewVC are vulnerable to CVE-2008-1290?
Vulnerable versions of ViewVC include 1.0.2 and 1.0.3.
4
Can CVE-2008-1290 be exploited remotely?
Yes, CVE-2008-1290 can be exploited remotely to access sensitive information.
5
Which software does CVE-2008-1290 impact?
CVE-2008-1290 specifically impacts ViewVC versions 1.0.2 and 1.0.3.