5
CVSSv2

CVE-2012-3357

Published: 22/07/2012 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC prior to 1.1.15 does not properly handle log messages when a readable path is copied from an unreadable path, which allows remote malicious users to obtain sensitive information, related to a "log msg leak."

Vulnerable Product Search on Vulmon Subscribe to Product

viewvc viewvc 1.1.8

viewvc viewvc 1.1.7

viewvc viewvc 1.1.11

viewvc viewvc 1.1.3

viewvc viewvc 1.0.1

viewvc viewvc 1.0.2

viewvc viewvc 0.9.1

viewvc viewvc 0.9

viewvc viewvc

viewvc viewvc 1.1.6

viewvc viewvc 1.1.2

viewvc viewvc 1.0.10

viewvc viewvc 1.0.3

viewvc viewvc 1.0.6

viewvc viewvc 1.0.9

viewvc viewvc 0.8

viewvc viewvc 1.1.13

viewvc viewvc 1.1.12

viewvc viewvc 1.1.1

viewvc viewvc 1.1.0

viewvc viewvc 1.0.0

viewvc viewvc 1.0.11

viewvc viewvc 1.0.7

viewvc viewvc 1.0.5

viewvc viewvc 0.9.4

viewvc viewvc 1.1.4

viewvc viewvc 1.1.5

viewvc viewvc 1.1.10

viewvc viewvc 1.1.9

viewvc viewvc 1.0.8

viewvc viewvc 1.0.4

viewvc viewvc 0.9.3

viewvc viewvc 0.9.2

Vendor Advisories

Debian Bug report logs - #671482 CVE-2009-5024: Possible excessive resource use when commit database feature enabled Package: viewvc; Maintainer for viewvc is Lev Lamberov <dogsleg@debianorg>; Source for viewvc is src:viewvc (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Fri, ...
Debian Bug report logs - #679069 CVE-2012-3356 / CVE-2012-3357 Package: viewvc; Maintainer for viewvc is Lev Lamberov <dogsleg@debianorg>; Source for viewvc is src:viewvc (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Tue, 26 Jun 2012 07:45:11 UTC Severity: grave Tags: patch ...