fkie_cve-2012-3356
Vulnerability from fkie_nvd
Published
2012-07-22 16:55
Modified
2025-04-11 00:51
Severity ?
Summary
The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
References
secalert@redhat.comhttp://osvdb.org/83225
secalert@redhat.comhttp://viewvc.tigris.org/issues/show_bug.cgi?id=353
secalert@redhat.comhttp://viewvc.tigris.org/source/browse/%2Acheckout%2A/viewvc/tags/1.1.15/CHANGES
secalert@redhat.comhttp://viewvc.tigris.org/source/browse/viewvc?view=rev&revision=2755
secalert@redhat.comhttp://viewvc.tigris.org/source/browse/viewvc?view=rev&revision=2756
secalert@redhat.comhttp://viewvc.tigris.org/source/browse/viewvc?view=rev&revision=2757
secalert@redhat.comhttp://viewvc.tigris.org/source/browse/viewvc?view=rev&revision=2759
secalert@redhat.comhttp://viewvc.tigris.org/source/browse/viewvc?view=rev&revision=2760
secalert@redhat.comhttp://www.debian.org/security/2012/dsa-2563
secalert@redhat.comhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:134
secalert@redhat.comhttp://www.openwall.com/lists/oss-security/2012/06/25/8
secalert@redhat.comhttp://www.securityfocus.com/bid/54197
secalert@redhat.comhttps://exchange.xforce.ibmcloud.com/vulnerabilities/76614
secalert@redhat.comhttps://lwn.net/Articles/505096/
secalert@redhat.comhttps://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0175
af854a3a-2127-422b-91ae-364da2661108http://osvdb.org/83225
af854a3a-2127-422b-91ae-364da2661108http://viewvc.tigris.org/issues/show_bug.cgi?id=353
af854a3a-2127-422b-91ae-364da2661108http://viewvc.tigris.org/source/browse/%2Acheckout%2A/viewvc/tags/1.1.15/CHANGES
af854a3a-2127-422b-91ae-364da2661108http://viewvc.tigris.org/source/browse/viewvc?view=rev&revision=2755
af854a3a-2127-422b-91ae-364da2661108http://viewvc.tigris.org/source/browse/viewvc?view=rev&revision=2756
af854a3a-2127-422b-91ae-364da2661108http://viewvc.tigris.org/source/browse/viewvc?view=rev&revision=2757
af854a3a-2127-422b-91ae-364da2661108http://viewvc.tigris.org/source/browse/viewvc?view=rev&revision=2759
af854a3a-2127-422b-91ae-364da2661108http://viewvc.tigris.org/source/browse/viewvc?view=rev&revision=2760
af854a3a-2127-422b-91ae-364da2661108http://www.debian.org/security/2012/dsa-2563
af854a3a-2127-422b-91ae-364da2661108http://www.mandriva.com/security/advisories?name=MDVSA-2013:134
af854a3a-2127-422b-91ae-364da2661108http://www.openwall.com/lists/oss-security/2012/06/25/8
af854a3a-2127-422b-91ae-364da2661108http://www.securityfocus.com/bid/54197
af854a3a-2127-422b-91ae-364da2661108https://exchange.xforce.ibmcloud.com/vulnerabilities/76614
af854a3a-2127-422b-91ae-364da2661108https://lwn.net/Articles/505096/
af854a3a-2127-422b-91ae-364da2661108https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0175
Impacted products
Vendor Product Version
viewvc viewvc *
viewvc viewvc 0.8
viewvc viewvc 0.9
viewvc viewvc 0.9.1
viewvc viewvc 0.9.2
viewvc viewvc 0.9.3
viewvc viewvc 0.9.4
viewvc viewvc 1.0.0
viewvc viewvc 1.0.1
viewvc viewvc 1.0.2
viewvc viewvc 1.0.3
viewvc viewvc 1.0.4
viewvc viewvc 1.0.5
viewvc viewvc 1.0.6
viewvc viewvc 1.0.7
viewvc viewvc 1.0.8
viewvc viewvc 1.0.9
viewvc viewvc 1.0.10
viewvc viewvc 1.0.11
viewvc viewvc 1.1.0
viewvc viewvc 1.1.1
viewvc viewvc 1.1.2
viewvc viewvc 1.1.3
viewvc viewvc 1.1.4
viewvc viewvc 1.1.5
viewvc viewvc 1.1.6
viewvc viewvc 1.1.7
viewvc viewvc 1.1.8
viewvc viewvc 1.1.9
viewvc viewvc 1.1.10
viewvc viewvc 1.1.11
viewvc viewvc 1.1.12
viewvc viewvc 1.1.13



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "E32A343E-869D-4BEB-AB65-094C1E548812",
              "versionEndIncluding": "1.1.14",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:0.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "3DB85009-6655-4288-B06B-18074F69EF67",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:0.9:*:*:*:*:*:*:*",
              "matchCriteriaId": "8344FE80-0BEF-4FE4-A87C-8A03CF83406B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:0.9.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "2C1671BC-6DF0-4FD3-991B-B342E1DA1EB7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:0.9.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "7D01FEFC-DE9B-4CBD-9F3E-C5F37A7FA70C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:0.9.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "67365FF3-29FE-40BD-8986-467AFCDD2210",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:0.9.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "90060F09-83C0-480F-AAF6-5006CD439E7B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.0.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "59DBEDF6-248F-4850-B50C-61835DB89374",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.0.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "007977CF-1BF9-4713-AFDF-50DEE2530AD5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.0.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "793F6DB3-A6C2-4813-BD2D-AF34D85F6CCA",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.0.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "1B6F2BC5-D099-427C-9513-75551ABF1997",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.0.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "4748AA05-D2ED-4365-83AE-74CD33592B5D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.0.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "91ADB624-1826-405C-BB1E-3D286ED03D5A",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.0.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "A4AE31C7-1929-48A4-8A3A-860A110E4820",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.0.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "F71721BF-9010-4595-96F8-CF499B0FFE6D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.0.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "96AD0DD2-206B-4231-B09E-9B83F6E0239E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.0.9:*:*:*:*:*:*:*",
              "matchCriteriaId": "2A7F4AAD-EB09-47F1-A7B7-5436E766A0C6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.0.10:*:*:*:*:*:*:*",
              "matchCriteriaId": "E0D457A6-C530-42AC-9BCF-640A89D9BF5C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.0.11:*:*:*:*:*:*:*",
              "matchCriteriaId": "6AD3EFA7-5B31-453C-8319-8A943C149731",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.1.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "8ECD4F7E-011C-4E92-9D8E-AC378B204C05",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.1.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "4FE78493-E4EB-4555-BA56-A29AFE680B56",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.1.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "C076220E-CFB1-44B0-9884-840F4C5B4F9A",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.1.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "77350E39-A3A7-463E-BF70-D1BD99F7C23E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.1.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "AB57E24E-00A7-4099-8135-64B0E165FEBF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.1.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "46A3CC38-5905-40B1-BD8B-EA378D8F5106",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.1.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "402EB3C0-3B69-4EF5-8342-1BCC411E8788",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.1.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "276B3475-7B55-48CC-8F34-0439AE5B8291",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.1.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "14320E94-C5AA-4E5B-8005-C38BD4F9989F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.1.9:*:*:*:*:*:*:*",
              "matchCriteriaId": "110D1159-D604-443F-85F8-670570FF7679",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.1.10:*:*:*:*:*:*:*",
              "matchCriteriaId": "7419BB99-B279-44B7-A41F-765805695DF7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.1.11:*:*:*:*:*:*:*",
              "matchCriteriaId": "D5D05FE1-6EA9-4C71-8F4E-8507C5F87952",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.1.12:*:*:*:*:*:*:*",
              "matchCriteriaId": "38AA489B-4287-48D9-B771-C066E41A7B52",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:viewvc:viewvc:1.1.13:*:*:*:*:*:*:*",
              "matchCriteriaId": "B8E798B8-B3E0-4359-BEFE-777F71AB4ECB",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ]
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows remote attackers to bypass intended access restrictions via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "La vista SVN de funcionalidad remota (lib/vclib/svn/svn_ra.py) en ViewVC anterior a v1.1.15 no realiza correctamente la autorizaci\u00f3n, permite a atacantes remotos eludir restricciones de acceso a trav\u00e9s destinados vectores no especificados."
    }
  ],
  "id": "CVE-2012-3356",
  "lastModified": "2025-04-11T00:51:21.963",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "MEDIUM",
        "cvssData": {
          "accessComplexity": "LOW",
          "accessVector": "NETWORK",
          "authentication": "NONE",
          "availabilityImpact": "NONE",
          "baseScore": 5.0,
          "confidentialityImpact": "NONE",
          "integrityImpact": "PARTIAL",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "version": "2.0"
        },
        "exploitabilityScore": 10.0,
        "impactScore": 2.9,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ]
  },
  "published": "2012-07-22T16:55:39.523",
  "references": [
    {
      "source": "secalert@redhat.com",
      "url": "http://osvdb.org/83225"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://viewvc.tigris.org/issues/show_bug.cgi?id=353"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://viewvc.tigris.org/source/browse/%2Acheckout%2A/viewvc/tags/1.1.15/CHANGES"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://viewvc.tigris.org/source/browse/viewvc?view=rev\u0026revision=2755"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://viewvc.tigris.org/source/browse/viewvc?view=rev\u0026revision=2756"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://viewvc.tigris.org/source/browse/viewvc?view=rev\u0026revision=2757"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://viewvc.tigris.org/source/browse/viewvc?view=rev\u0026revision=2759"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://viewvc.tigris.org/source/browse/viewvc?view=rev\u0026revision=2760"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://www.debian.org/security/2012/dsa-2563"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2013:134"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://www.openwall.com/lists/oss-security/2012/06/25/8"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://www.securityfocus.com/bid/54197"
    },
    {
      "source": "secalert@redhat.com",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/76614"
    },
    {
      "source": "secalert@redhat.com",
      "url": "https://lwn.net/Articles/505096/"
    },
    {
      "source": "secalert@redhat.com",
      "url": "https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0175"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://osvdb.org/83225"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://viewvc.tigris.org/issues/show_bug.cgi?id=353"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://viewvc.tigris.org/source/browse/%2Acheckout%2A/viewvc/tags/1.1.15/CHANGES"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://viewvc.tigris.org/source/browse/viewvc?view=rev\u0026revision=2755"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://viewvc.tigris.org/source/browse/viewvc?view=rev\u0026revision=2756"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://viewvc.tigris.org/source/browse/viewvc?view=rev\u0026revision=2757"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://viewvc.tigris.org/source/browse/viewvc?view=rev\u0026revision=2759"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://viewvc.tigris.org/source/browse/viewvc?view=rev\u0026revision=2760"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.debian.org/security/2012/dsa-2563"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2013:134"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.openwall.com/lists/oss-security/2012/06/25/8"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.securityfocus.com/bid/54197"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/76614"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "https://lwn.net/Articles/505096/"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0175"
    }
  ],
  "sourceIdentifier": "secalert@redhat.com",
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Primary"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…