Bug 435349

Summary: viewvc: multiple security fixes in upstream version 1.0.5 (CVE-2008-1290, CVE-2008-1291, CVE-2008-1292)
Product: [Other] Security Response Reporter: David Rees <drees76>
Component: vulnerabilityAssignee: Bojan Smojver <bojan>
Status: CLOSED CURRENTRELEASE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: low    
Version: unspecifiedCC: bjohnson, lkundrak, security-response-team
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: 1.0.5-1.fc7 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2008-03-01 09:26:47 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 438854, 438855, 438856    
Bug Blocks:    

Description David Rees 2008-02-28 19:59:44 UTC
ViewVC has released a new version, 1.0.5 which has several security fixes in it.

Read the full announcement here:

http://viewvc.tigris.org/servlets/ReadMsg?list=announce&msgNo=7

Changelog is here:

http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?rev=HEAD

Security fixes noted in 1.0.5 changelog:

  * security fix: omit commits of all-forbidden files from query results
  * security fix: disallow direct URL navigation to hidden CVSROOT folder
  * security fix: strip forbidden paths from revision view
  * security fix: don't traverse log history thru forbidden locations
  * security fix: honor forbiddenness via diff view path parameters

Comment 1 Bojan Smojver 2008-02-28 21:25:32 UTC
Yep, got the announcement from Tigris folks.

Comment 2 Fedora Update System 2008-02-28 22:22:54 UTC
viewvc-1.0.5-1.fc8 has been submitted as an update for Fedora 8

Comment 3 Lubomir Kundrak 2008-02-28 22:41:15 UTC
CVE name has been requested.

Comment 4 Fedora Update System 2008-03-01 09:26:45 UTC
viewvc-1.0.5-1.fc7 has been pushed to the Fedora 7 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2008-03-01 09:27:37 UTC
viewvc-1.0.5-1.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 6 Lubomir Kundrak 2008-03-25 16:52:57 UTC
*** Bug 438854 has been marked as a duplicate of this bug. ***

Comment 7 Lubomir Kundrak 2008-03-25 16:53:03 UTC
*** Bug 438855 has been marked as a duplicate of this bug. ***

Comment 8 Lubomir Kundrak 2008-03-25 16:53:13 UTC
*** Bug 438856 has been marked as a duplicate of this bug. ***