Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 198590 - dev-util/subversion Information disclosure (CVE-2007-2448)
Summary: dev-util/subversion Information disclosure (CVE-2007-2448)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://subversion.tigris.org/security...
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-11-09 19:27 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2020-04-03 22:49 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-11-09 19:27:49 UTC
Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit.

----

More elaborate description at $URL.

Upstream patch: http://svn.collab.net/viewvc/svn?view=rev&revision=25185
Comment 1 Benedikt Böhm (RETIRED) gentoo-dev 2007-11-10 20:44:15 UTC
i have just added 1.4.5 to the tree with many fixes. this is the next candidate for stabilization
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-11-11 08:39:26 UTC
Thx Benedikt. Is this one ready for stable marking now?
Comment 3 Arfrever Frehtes Taifersar Arahesis (RETIRED) gentoo-dev 2007-11-11 16:31:34 UTC
(In reply to comment #2)
> Is this one ready for stable marking now?

Yes. There's nothing new for UNIX-like systems. 1.4.5 contains only a fix for Windows.
Comment 4 Robert Buchholz (RETIRED) gentoo-dev 2007-11-11 17:10:30 UTC
Arches, please test and mark stable dev-util/subversion-1.4.5.
Target keywords : "alpha amd64 arm hppa ia64 mips ppc ppc64 s390 sh sparc x86"
Comment 5 Robert Buchholz (RETIRED) gentoo-dev 2007-11-11 17:17:02 UTC
Oh, wait. Hollow, is that an authoritative answer?
Comment 6 Arfrever Frehtes Taifersar Arahesis (RETIRED) gentoo-dev 2007-11-11 17:20:52 UTC
(In reply to comment #5)
> Oh, wait. Hollow, is that an authoritative answer?

Yes. I belong to Subversion upstream and I don't have bad intentions.

http://subversion.tigris.org/servlets/ReadMsg?list=users&msgNo=69413

1.4.5 works identically as 1.4.4 on GNU/Linux and *BSD.
Comment 7 Benedikt Böhm (RETIRED) gentoo-dev 2007-11-11 17:50:22 UTC
yep, go for stabilization :)
Comment 8 Robert Buchholz (RETIRED) gentoo-dev 2007-11-11 17:53:25 UTC
(In reply to comment #6)
> Yes. I belong to Subversion upstream and I don't have bad intentions.

I didn't mean you have bad intentions, just that I first thought you were in the Gentoo Apache team. And we have 1.3.* stable right now, so this is not a tiny bump.
Comment 9 Dawid Węgliński (RETIRED) gentoo-dev 2007-11-11 18:54:08 UTC
x86 stable
Comment 10 Markus Ullmann (RETIRED) gentoo-dev 2007-11-11 19:28:33 UTC
stable on sparc
Comment 11 Raúl Porcel (RETIRED) gentoo-dev 2007-11-11 20:09:01 UTC
alpha/ia64 stable
Comment 12 Jeroen Roovers (RETIRED) gentoo-dev 2007-11-12 16:57:52 UTC
Stable for HPPA, despite:

  IUSE.invalid                   1
   dev-util/subversion/subversion-1.4.5.ebuild: svnserve
Comment 13 Markus Rothe (RETIRED) gentoo-dev 2007-11-12 19:34:25 UTC
ppc64 stable
Comment 14 Tobias Scherbaum (RETIRED) gentoo-dev 2007-11-13 19:57:29 UTC
ppc stable
Comment 15 Chris Gianelloni (RETIRED) gentoo-dev 2007-11-14 01:16:45 UTC
amd64 done...
Comment 16 Robert Buchholz (RETIRED) gentoo-dev 2007-11-14 01:23:45 UTC
GLSA vote is open.

I vote NO
since this this vulnerability is rare and with little impact, quoting: "data is not commonly copied from a private location to a public one... only
reveal the contents of properties, not the revision's changed-paths
information.  And, of course, this bug does not permit anyone to see
file contents or directory listings that they should not."
Comment 17 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-11-14 08:57:54 UTC
voting NO too and closing.
Comment 18 Peter Volkov (RETIRED) gentoo-dev 2008-03-06 09:48:26 UTC
Does not affect current (2008.0) release. Removing release.