First published: Fri Jan 29 2010(Updated: )
ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discover private root names by reading this view.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ViewVC | =1.0.1 | |
ViewVC | =1.0.2 | |
ViewVC | =1.0.3 | |
ViewVC | =1.0.4 | |
ViewVC | =1.0.5 | |
ViewVC | =1.0.6 | |
ViewVC | =1.0.7 | |
ViewVC | =1.0.8 | |
ViewVC | =1.1.0 | |
ViewVC | =1.1.1 | |
ViewVC | =1.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0004 is considered a moderate severity vulnerability due to its potential to expose private root names.
To fix CVE-2010-0004, upgrade ViewVC to version 1.1.3 or later.
ViewVC versions 1.0.1 through 1.1.2 are affected by CVE-2010-0004.
CVE-2010-0004 can be exploited by remote attackers to discover private root names.
Yes, CVE-2010-0004 arises from the failure to use the proper authorizer for each root in ViewVC.