CVE-2010-0005: High severity viewvc ViewVC vulnerability
Published Jan 29, 2010
·Updated
query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might allow remote attackers to bypass intended access restrictions via a query.
Affected Software
11 affected components
viewvc ViewVC=1.0.2
viewvc ViewVC=1.0.1
viewvc ViewVC=1.0.5
viewvc ViewVC=1.1.0
viewvc ViewVC=1.1.1
viewvc ViewVC=1.0.3
viewvc ViewVC=1.0.4
viewvc ViewVC=1.0.6
viewvc ViewVC=1.0.8
viewvc ViewVC<=1.1.2
viewvc ViewVC=1.0.7
Remediation
Event History
Jan 29, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0005?
CVE-2010-0005 has been classified as a moderate severity vulnerability due to its potential to allow unauthorized access.
2
How do I fix CVE-2010-0005?
To fix CVE-2010-0005, upgrade to ViewVC version 1.1.3 or later, which addresses the vulnerability.
3
Which versions of ViewVC are affected by CVE-2010-0005?
CVE-2010-0005 affects ViewVC versions 1.0.1 through 1.1.2.
4
What can an attacker achieve by exploiting CVE-2010-0005?
Exploiting CVE-2010-0005 allows remote attackers to bypass access restrictions and potentially gain unauthorized access to restricted queries.
5
Is CVE-2010-0005 a remote code execution vulnerability?
No, CVE-2010-0005 is not a remote code execution vulnerability; it primarily affects access control.