From 7912c83c60c219279bbecb8eaa0561d62bba75ca Mon Sep 17 00:00:00 2001 From: simon Date: Tue, 7 Dec 2004 23:38:31 +0000 Subject: Document information leakage in viewcvs. --- security/vuxml/vuln.xml | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) (limited to 'security') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index bcdef076f859..157856cf3732 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -32,6 +32,31 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. --> + + viewcvs -- information leakage + + + viewcvs + 0.9.2_2 + + + + +

The hide_cvsroot and forbidden + configuration options are not properly honored by viewcvs + when exporting to a tar file which can lead to information + leakage.

+ +
+ + CAN-2004-0915 + + + 2004-11-25 + 2004-12-08 + +
+ cscope -- symlink attack vulnerability -- cgit