Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The package websvn before version 2.6.1-1 is vulnerable to arbitrary command execution. . Arch Linux Security Advisory ASA-202105-16 ========================================= Severity: High Date : 2021-05-25 CVE-ID : CVE-2021-32305 Package : websvn Type : arbitrary command execution Remote : Yes Link : https://security.archlinux.org/AVG-1969 Summary ====== The package websvn before version 2.6.1-1 is vulnerable to arbitrary command execution. Resolution ========= Upgrade to 2.6.1-1. # pacman -Syu "websvn> =2.6.1-1" The problem has been fixed upstream in version 2.6.1. Workaround ========= None. Description ========== WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter. Impact ===== A remote attacker can execute arbitrary shell commands on the server using a crafted search query. References ========= https://github.com/websvnphp/websvn/pull/142 https://github.com/websvnphp/websvn/commit/88fce56b7b9dbfc0fe2629217c3bff2c2e751920 https://security.archlinux.org/CVE-2021-32305 . Ubuntu Security Notice USN-1234-1 reveals a critical vulnerability in the XYZ application that allows unauthorized code execution. Update immediately.. websvn security advisory, arch linux command execution, high severity risks. . LinuxSecurity.com Team
Nitin Venkatesh discovered that websvn, a web viewer for Subversion repositories, is susceptible to cross-site scripting attacks via specially crafted file and directory names in repositories. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3572-1
- Fix CVE-2016-2511. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-657a1305aa 2016-03-20 22:04:03.377791 -------------------------------------------------------------------------------- Name : websvn Product : Fedora 23 Version : 2.3.3 Release : 12.fc23 URL : https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fsites.google.com%2Fview%2Fvn88-vn88com&followup=https%3A%2F%2Fsites.google.com%2Fview%2Fvn88-vn88com&ifkv=AdBytiOa3OwAAmtOSnC9TDUsO4xXtpIZ3cSXCpBSfErjstoPCwo3KVe-rRcHqY7fghdODcRfIJBf5Q&osid=1&passive=1209600&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S1914885879%3A1750217781873400// Summary : Online subversion repository browser Description : WebSVN offers a view onto your subversion repositories that's been designed to reflect the Subversion methodology. You can view the log of any file or directory and see a list of all the files changed, added or deleted in any given revision. You can also view the differences between two versions of a file so as to see exactly what was changed in a particular revision. -------------------------------------------------------------------------------- Update Information: - Fix CVE-2016-2511 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1310760 - CVE-2016-2511 websvn: reflected cross-site scripting [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1310760 [ 2 ] Bug #1310759 - CVE-2016-2511 websvn: reflected cross-site scripting [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1310759 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update websvn' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
- Fix CVE-2016-2511. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-11537160e9 2016-03-20 16:01:37.706621 -------------------------------------------------------------------------------- Name : websvn Product : Fedora 22 Version : 2.3.3 Release : 12.fc22 URL : https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fsites.google.com%2Fview%2Fvn88-vn88com&followup=https%3A%2F%2Fsites.google.com%2Fview%2Fvn88-vn88com&ifkv=AdBytiOQZ2dUdfmEMgcyNZ8idzChC8XFDbQJkfaTxrHWeF3Ya1LWEI-n97T4zfMTdoIYpA-cgv0Q1g&osid=1&passive=1209600&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S1781429062%3A1750217749713434// Summary : Online subversion repository browser Description : WebSVN offers a view onto your subversion repositories that's been designed to reflect the Subversion methodology. You can view the log of any file or directory and see a list of all the files changed, added or deleted in any given revision. You can also view the differences between two versions of a file so as to see exactly what was changed in a particular revision. -------------------------------------------------------------------------------- Update Information: - Fix CVE-2016-2511 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1310760 - CVE-2016-2511 websvn: reflected cross-site scripting [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1310760 [ 2 ] Bug #1310759 - CVE-2016-2511 websvn: reflected cross-site scripting [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1310759 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update websvn' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
James Clawson discovered that websvn, a web viewer for Subversion repositories, would follow symlinks in a repository when presenting a file for download. An attacker with repository write access could thereby access any file on disk readable by the user the webserver . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3137-1
Multiple vulnerabilities in WebSVN allow for file overwrite and information disclosure.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: WebSVN: Multiple vulnerabilities Date: March 09, 2009 Bugs: #243852 ID: 200903-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities in WebSVN allow for file overwrite and information disclosure. Background ========= WebSVN is a web-based browsing tool for Subversion repositories written in PHP. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/websvn < 2.1.0 > = 2.1.0 Description ========== * James Bercegay of GulfTech Security reported a Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl() function in index.php (CVE-2008-5918) and a directory traversal vulnerability in rss.php when magic_quotes_gpc is disabled (CVE-2008-5919). * Bas van Schaik reported that listing.php does not properly enforce access restrictions when using an SVN authz file to authenticate users (CVE-2009-0240). Impact ===== A remote attacker can exploit these vulnerabilities to overwrite arbitrary files, to read changelogs or diffs for restricted projects and to hijack a user's session. Workaround ========= There is no known workaround at this time. Resolution ========= All WebSVN users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-apps/websvn-2.1.0" References ========= [ 1 ] CVE-2008-5918 https://www.cve.org/CVERecord?id=CVE-2008-5918 [ 2 ] CVE-2008-5919 https://www.cve.org/CVERecord?id=CVE-2008-5919 [ 3 ] CVE-2009-0240 https://www.cve.org/CVERecord?id=CVE-2009-0240 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200903-20 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Bas van Schaik discovered that WebSVN, a tool to view Subversion repositories over the web, did not properly restrict access to private repositories, allowing a remote attacker to read significant parts of their content. . - ------------------------------------------------------------------------ Debian Security Advisory DSA-1725-1
Get the latest Linux and open source security news straight to your inbox.