CVE-2009-3619: Medium severity viewvc vulnerability
Published Nov 10, 2009
·Updated
Unspecified vulnerability in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 has unknown impact and remote attack vectors related to "printing illegal parameter names and values."
Affected Software
10 affected components
viewvc ViewVC=1.0.1
viewvc ViewVC=1.0.2
viewvc ViewVC=1.0.3
viewvc ViewVC=1.0.4
viewvc ViewVC=1.0.5
viewvc ViewVC=1.0.6
viewvc ViewVC=1.0.7
viewvc ViewVC=1.0.8
viewvc ViewVC=1.1.0
viewvc ViewVC=1.1.1
Remediation
Patch Available
Event History
Nov 10, 2009
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-3619?
CVE-2009-3619 has an unspecified severity but is known to allow remote attack vectors.
2
How do I fix CVE-2009-3619?
To fix CVE-2009-3619, upgrade to ViewVC version 1.0.9 or 1.1.2 or later.
3
What versions of ViewVC are affected by CVE-2009-3619?
CVE-2009-3619 affects ViewVC versions 1.0.1 through 1.0.8 and 1.1.0 through 1.1.1.
4
What types of attacks can exploit CVE-2009-3619?
CVE-2009-3619 can be exploited through remote attacks that involve printing illegal parameter names and values.
5
Is there a patch available for CVE-2009-3619?
Yes, patches are available through the updates that upgrade to ViewVC versions 1.0.9 or 1.1.2.