First published: Thu Apr 11 2013(Updated: )
Local file exposure on Windows installations
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/sabre/dav | >=1.6.0<1.6.9>=1.7.0<1.7.7>=1.8.0<1.8.5 | |
composer/sabre/dav | >=1.6.0<1.6.9 | 1.6.9 |
composer/sabre/dav | >=1.8.0<1.8.5 | 1.8.5 |
composer/sabre/dav | >=1.7.0<1.7.7 | 1.7.7 |
All of | ||
Any of | ||
Fruux Sabredav | >=1.6.0<1.6.9 | |
Fruux Sabredav | >=1.7.0<1.7.7 | |
Fruux Sabredav | >=1.8.0<1.8.5 | |
Microsoft Windows | ||
All of | ||
Any of | ||
ownCloud | >=4.0.0<4.0.14 | |
ownCloud | >=4.5.0<4.5.9 | |
ownCloud | >=5.0.0<5.0.4 | |
Microsoft Windows | ||
Fruux Sabredav | >=1.6.0<1.6.9 | |
Fruux Sabredav | >=1.7.0<1.7.7 | |
Fruux Sabredav | >=1.8.0<1.8.5 | |
Microsoft Windows | ||
ownCloud | >=4.0.0<4.0.14 | |
ownCloud | >=4.5.0<4.5.9 | |
ownCloud | >=5.0.0<5.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1939 is considered to have moderate severity due to its potential to allow file exposure on Windows installations.
To fix CVE-2013-1939, upgrade SabreDAV to version 1.6.9, 1.7.7, or 1.8.5 or later.
CVE-2013-1939 affects SabreDAV versions prior to 1.6.9, 1.7.7, and 1.8.5.
Yes, CVE-2013-1939 is specifically related to Windows installations of SabreDAV.
The implication of CVE-2013-1939 is that an attacker could potentially exploit this vulnerability to read arbitrary files on vulnerable installations.