Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 298127 (CVE-2010-0004)

Summary: <www-apps/viewvc-1.1.3: Security vulnerabilities (CVE-2010-{0004,0005})
Product: Gentoo Security Reporter: Arfrever Frehtes Taifersar Arahesis (RETIRED) <arfrever>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: web-apps
Priority: High    
Version: unspecified   
Hardware: All   
OS: All   
URL: http://viewvc.tigris.org/source/browse/viewvc/tags/1.1.3/CHANGES?revision=HEAD
Whiteboard: B4 [noglsa]
Package list:
Runtime testing required: ---

Description Arfrever Frehtes Taifersar Arahesis (RETIRED) gentoo-dev 2009-12-23 18:51:42 UTC
<www-apps/viewvc-1.1.3 has some minor security vulnerabilities.

CHANGES file contains:
  * security fix: add root listing support of per-root authz config
  * security fix: query.py requires 'forbidden' authorizer (or none) in config
Comment 1 Arfrever Frehtes Taifersar Arahesis (RETIRED) gentoo-dev 2009-12-23 18:53:23 UTC
Stabilize www-apps/viewvc-1.1.3.
Comment 2 Raúl Porcel (RETIRED) gentoo-dev 2009-12-26 11:53:21 UTC
sparc/x86 stable
Comment 3 Markus Meier gentoo-dev 2009-12-31 18:17:51 UTC
amd64 stable
Comment 4 Joe Jezak (RETIRED) gentoo-dev 2010-01-07 15:59:54 UTC
Marked ppc stable.
Comment 5 Tobias Heinlein (RETIRED) gentoo-dev 2010-03-01 12:25:53 UTC
CVE-2010-0004 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0004):
  ViewVC before 1.1.3 composes the root listing view without using the
  authorizer for each root, which might allow remote attackers to
  discover private root names by reading this view.

Comment 6 Tobias Heinlein (RETIRED) gentoo-dev 2010-03-01 12:26:37 UTC
All arches done, I vote NO.
Comment 7 Tobias Heinlein (RETIRED) gentoo-dev 2010-03-01 12:28:02 UTC
CVE-2010-0005 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0005):
  query.py in the query interface in ViewVC before 1.1.3 does not
  reject configurations that specify an unsupported authorizer for a
  root, which might allow remote attackers to bypass intended access
  restrictions via a query.

Comment 8 Stefan Behte (RETIRED) gentoo-dev Security 2010-03-06 16:19:15 UTC
NO, too. Closing noglsa.