CVE Vulnerabilities

CVE-2008-4325

Published: Sep 30, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which allows remote attackers to cause content to be misinterpreted by the browser via a content-type parameter that is inconsistent with the requested object. NOTE: this issue might not be a vulnerability, since it requires attacker access to the repository that is being viewed.

Affected Software

NameVendorStart VersionEnd Version
ViewvcViewvc1.0.5 (including)1.0.5 (including)
ViewvcUbuntugutsy*
ViewvcUbuntuhardy*
ViewvcUbuntuintrepid*
ViewvcUbuntujaunty*
ViewvcUbuntukarmic*
ViewvcUbuntuupstream*

References