5
CVSSv2

CVE-2004-0915

Published: 10/01/2005 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Multiple unknown vulnerabilities in viewcvs prior to 0.9.2, when exporting a repository as a tar archive, does not properly implement the hide_cvsroot and forbidden settings, which could allow remote malicious users to gain sensitive information.

Vulnerable Product Search on Vulmon Subscribe to Product

viewcvs viewcvs 0.9.2

debian debian linux 3.0

Vendor Advisories

Haris Sehic discovered several vulnerabilities in viewcvs, a utility for viewing CVS and Subversion repositories via HTTP When exporting a repository as a tar archive the hide_cvsroot and forbidden settings were not honoured enough When upgrading the package for woody, please make a copy of your /etc/viewcvs/viewcvsconf file if you have manually ...