Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Gentoo: GLSA-200903-20 Normal: WebSVN File Overwrite and Info Leak

gentoo
Calendar Grey March 9, 2009
Scroller Gentoo
WebSVN contains several security flaws on Gentoo Linux; an upgrade is necessary to avert data leaks and file replacement.
Multiple vulnerabilities in WebSVN allow for file overwrite and information disclosure.

Summary

Gentoo Linux Security Advisory GLSA 200903-20 https://security.gentoo.org/ Severity: Normal Title: WebSVN: Multiple vulnerabilities Date: March 09, 2009 Bugs: #243852 ID: 200903-20

Synopsis ======= Multiple vulnerabilities in WebSVN allow for file overwrite and information disclosure.
Background ========= WebSVN is a web-based browsing tool for Subversion repositories written in PHP.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/websvn < 2.1.0 >= 2.1.0
========== * James Bercegay of GulfTech Security reported a Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl() function in index.php (CVE-2008-5918) and a directory ...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround