2.1
CVSSv2

CVE-2007-2448

Published: 14/06/2007 Updated: 06/11/2012
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:N/AC:H/Au:S/C:P/I:N/A:N

Vulnerability Summary

Subversion 1.4.3 and previous versions does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit.

Vulnerable Product Search on Vulmon Subscribe to Product

subversion subversion

Vendor Advisories

Debian Bug report logs - #428194 CVE-2007-2448: "security flaw in 'svn prop*' commands" Package: subversion; Maintainer for subversion is James McCoy <jamessan@debianorg>; Source for subversion is src:subversion (PTS, buildd, popcon) Reported by: Florian Weimer <fw@denebenyode> Date: Sat, 9 Jun 2007 19:03:02 UTC ...
It was discovered that Subversion incorrectly handled certain ‘partial access’ privileges in rare scenarios Remote authenticated users could use this flaw to obtain sensitive information (revision properties) This issue only applied to Ubuntu 606 LTS (CVE-2007-2448) ...