Bug 435349 - viewvc: multiple security fixes in upstream version 1.0.5 (CVE-2008-1290, CVE-2008-1291, CVE-2008-1292)
viewvc: multiple security fixes in upstream version 1.0.5 (CVE-2008-1290, CVE...
Status: CLOSED CURRENTRELEASE
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity medium
: ---
: ---
Assigned To: Bojan Smojver
Fedora Extras Quality Assurance
:
: CVE-2008-1290 CVE-2008-1291 CVE-2008-1292 (view as bug list)
Depends On: CVE-2008-1290 CVE-2008-1291 CVE-2008-1292
Blocks:
  Show dependency treegraph
 
Reported: 2008-02-28 14:59 EST by David Rees
Modified: 2008-03-31 03:00 EDT (History)
3 users (show)

See Also:
Fixed In Version: 1.0.5-1.fc7
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2008-03-01 04:26:47 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description David Rees 2008-02-28 14:59:44 EST
ViewVC has released a new version, 1.0.5 which has several security fixes in it.

Read the full announcement here:

http://viewvc.tigris.org/servlets/ReadMsg?list=announce&msgNo=7

Changelog is here:

http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?rev=HEAD

Security fixes noted in 1.0.5 changelog:

  * security fix: omit commits of all-forbidden files from query results
  * security fix: disallow direct URL navigation to hidden CVSROOT folder
  * security fix: strip forbidden paths from revision view
  * security fix: don't traverse log history thru forbidden locations
  * security fix: honor forbiddenness via diff view path parameters
Comment 1 Bojan Smojver 2008-02-28 16:25:32 EST
Yep, got the announcement from Tigris folks.
Comment 2 Fedora Update System 2008-02-28 17:22:54 EST
viewvc-1.0.5-1.fc8 has been submitted as an update for Fedora 8
Comment 3 Lubomir Kundrak 2008-02-28 17:41:15 EST
CVE name has been requested.
Comment 4 Fedora Update System 2008-03-01 04:26:45 EST
viewvc-1.0.5-1.fc7 has been pushed to the Fedora 7 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 5 Fedora Update System 2008-03-01 04:27:37 EST
viewvc-1.0.5-1.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 6 Lubomir Kundrak 2008-03-25 12:52:57 EDT
*** Bug 438854 has been marked as a duplicate of this bug. ***
Comment 7 Lubomir Kundrak 2008-03-25 12:53:03 EDT
*** Bug 438855 has been marked as a duplicate of this bug. ***
Comment 8 Lubomir Kundrak 2008-03-25 12:53:13 EDT
*** Bug 438856 has been marked as a duplicate of this bug. ***

Note You need to log in before you can comment on or make changes to this bug.