diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index f4f6d0970fa7..0b2220884dc0 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -32,6 +32,42 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. --> + + subversion -- WebDAV fails to protect metadata + + + subversion + subversion-perl + subversion-python + 1.0.8 + + + + +

In some situations, subversion metadata may be unexpectedly + disclosed via WebDAV. A subversion advisory states:

+
+

mod_authz_svn, the Apache httpd module which does path-based + authorization on Subversion repositories, is not correctly + protecting all metadata on unreadable paths.

+

This security issue is not about revealing the contents + of protected files: it only reveals metadata about + protected areas such as paths and log messages. This may + or may not be important to your organization, depending + on how you're using path-based authorization, and the + sensitivity of the metadata.

+
+ +
+ + CAN-2004-0749 + http://subversion.tigris.org/security/CAN-2004-0749-advisory.txt + + + 2004-09-15 + 2004-09-26 + +
lha -- numerous vulnerabilities when extracting archives