Bug 435349 - viewvc: multiple security fixes in upstream version 1.0.5 (CVE-2008-1290, CVE-2008-1291, CVE-2008-1292)
Summary: viewvc: multiple security fixes in upstream version 1.0.5 (CVE-2008-1290, CVE...
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability   
(Show other bugs)
Version: unspecified
Hardware: All
OS: Linux
low
medium
Target Milestone: ---
Assignee: Bojan Smojver
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Keywords:
: CVE-2008-1290 CVE-2008-1291 CVE-2008-1292 (view as bug list)
Depends On: CVE-2008-1290, CVE-2008-1290 CVE-2008-1291, CVE-2008-1291 CVE-2008-1292, CVE-2008-1292
Blocks:
TreeView+ depends on / blocked
 
Reported: 2008-02-28 19:59 UTC by David Rees
Modified: 2008-03-31 07:00 UTC (History)
3 users (show)

Fixed In Version: 1.0.5-1.fc7
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2008-03-01 09:26:47 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

Description David Rees 2008-02-28 19:59:44 UTC
ViewVC has released a new version, 1.0.5 which has several security fixes in it.

Read the full announcement here:

http://viewvc.tigris.org/servlets/ReadMsg?list=announce&msgNo=7

Changelog is here:

http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?rev=HEAD

Security fixes noted in 1.0.5 changelog:

  * security fix: omit commits of all-forbidden files from query results
  * security fix: disallow direct URL navigation to hidden CVSROOT folder
  * security fix: strip forbidden paths from revision view
  * security fix: don't traverse log history thru forbidden locations
  * security fix: honor forbiddenness via diff view path parameters

Comment 1 Bojan Smojver 2008-02-28 21:25:32 UTC
Yep, got the announcement from Tigris folks.

Comment 2 Fedora Update System 2008-02-28 22:22:54 UTC
viewvc-1.0.5-1.fc8 has been submitted as an update for Fedora 8

Comment 3 Lubomir Kundrak 2008-02-28 22:41:15 UTC
CVE name has been requested.

Comment 4 Fedora Update System 2008-03-01 09:26:45 UTC
viewvc-1.0.5-1.fc7 has been pushed to the Fedora 7 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2008-03-01 09:27:37 UTC
viewvc-1.0.5-1.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 6 Lubomir Kundrak 2008-03-25 16:52:57 UTC
*** Bug 438854 has been marked as a duplicate of this bug. ***

Comment 7 Lubomir Kundrak 2008-03-25 16:53:03 UTC
*** Bug 438855 has been marked as a duplicate of this bug. ***

Comment 8 Lubomir Kundrak 2008-03-25 16:53:13 UTC
*** Bug 438856 has been marked as a duplicate of this bug. ***


Note You need to log in before you can comment on or make changes to this bug.