Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-3315

Опубликовано: 04 окт. 2010
Источник: ubuntu
Приоритет: medium
CVSS2: 6

Описание

authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.

РелизСтатусПримечание
dapper

not-affected

1.3.1-3ubuntu1.2
devel

not-affected

1.6.12dfsg-2ubuntu1
hardy

not-affected

1.4.6dfsg1-2ubuntu1.1
jaunty

ignored

end of life
karmic

released

1.6.5dfsg-1ubuntu1.1
lucid

released

1.6.6dfsg-2ubuntu1.1
maverick

released

1.6.12dfsg-1ubuntu1.1
upstream

released

1.5.8,1.6.13,1.6.12dfsg-2

Показывать по

6 Medium

CVSS2

Связанные уязвимости

redhat
больше 14 лет назад

authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.

nvd
больше 14 лет назад

authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.

debian
больше 14 лет назад

authz.c in the mod_dav_svn module for the Apache HTTP Server, as distr ...

github
около 3 лет назад

authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.

oracle-oval
больше 14 лет назад

ELSA-2011-0258: subversion security update (MODERATE)

6 Medium

CVSS2