|
|
| |
|
| |
subversion: restriction bypass
| Package(s): | subversion |
CVE #(s): | CVE-2010-3315
|
| Created: | October 11, 2010 |
Updated: | February 16, 2011 |
| Description: |
From the Debian advisory:
Kamesh Jayachandran and C. Michael Pilat discovered that the mod_dav_svn
module of subversion, a version control system, is not properly enforcing
access rules which are scope-limited to named repositories. If the
SVNPathAuthz option is set to "short_circuit" set this may enable an
unprivileged attacker to bypass intended access restrictions and disclose
or modify repository content.
|
| Alerts: |
|
( Log in to post comments)
|
|
|