First published: Mon May 30 2011(Updated: )
An unintended file contents disclosure flaw was found in the way mod_dav_svn module of the subversion concurrent version control system processed certain URLs, when path-access control for files and directories was enabled. A remote attacker could use this flaw to obtain information, which should be otherwise prohibited by the authorization subsystem. Acknowledgements: Red Hat would like to thank the Apache Subversion project for reporting this issue. Upstream acknowledges Kamesh Jayachandran of CollabNet, Inc. as the original reporter.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Subversion | =1.5.5 | |
Apache Subversion | =1.5.3 | |
Apache Subversion | =1.5.7 | |
Apache Subversion | =1.5.8 | |
Apache Subversion | =1.5.2 | |
Apache Subversion | =1.5.4 | |
Apache Subversion | =1.5.1 | |
Apache Subversion | =1.5.6 | |
Apache Subversion | =1.5.0 | |
Apache Subversion | =1.6.10 | |
Apache Subversion | =1.6.2 | |
Apache Subversion | =1.6.16 | |
Apache Subversion | =1.6.5 | |
Apache Subversion | =1.6.3 | |
Apache Subversion | =1.6.8 | |
Apache Subversion | =1.6.13 | |
Apache Subversion | =1.6.0 | |
Apache Subversion | =1.6.7 | |
Apache Subversion | =1.6.12 | |
Apache Subversion | =1.6.1 | |
Apache Subversion | =1.6.4 | |
Apache Subversion | =1.6.15 | |
Apache Subversion | =1.6.11 | |
Apache Subversion | =1.6.14 | |
Apache Subversion | =1.6.6 | |
Apache Subversion | =1.6.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.