php-sabredav-Sabre_DAV: local file exposure
| Package(s): | php-sabredav-Sabre_DAV |
CVE #(s): | CVE-2013-1939
|
| Created: | May 13, 2013 |
Updated: | May 15, 2013 |
| Description: |
From the Red Hat bugzilla:
A local file exposure flaw was found in the way HTML browser plug-in of SabreDAV, a WebDAV framework for the PHP language, processed certain file system paths for icon and image files on certain platforms. A remote attacker could provide a specially-crafted icon / image file location that, when processed by an application using the SabreDav framework, would allow them to (remotely) obtain arbitary system file, accessible with the privileges of that SabreDAV application. |
| Alerts: |
|