CVE Vulnerabilities

CVE-2010-0005

Published: Jan 29, 2010 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might allow remote attackers to bypass intended access restrictions via a query.

Affected Software

Name Vendor Start Version End Version
Viewvc Viewvc * 1.1.2 (including)
Viewvc Viewvc 1.0.1 (including) 1.0.1 (including)
Viewvc Viewvc 1.0.2 (including) 1.0.2 (including)
Viewvc Viewvc 1.0.3 (including) 1.0.3 (including)
Viewvc Viewvc 1.0.4 (including) 1.0.4 (including)
Viewvc Viewvc 1.0.5 (including) 1.0.5 (including)
Viewvc Viewvc 1.0.6 (including) 1.0.6 (including)
Viewvc Viewvc 1.0.7 (including) 1.0.7 (including)
Viewvc Viewvc 1.0.8 (including) 1.0.8 (including)
Viewvc Viewvc 1.1.0 (including) 1.1.0 (including)
Viewvc Viewvc 1.1.1 (including) 1.1.1 (including)
Viewvc Ubuntu hardy *
Viewvc Ubuntu intrepid *
Viewvc Ubuntu jaunty *
Viewvc Ubuntu karmic *
Viewvc Ubuntu lucid *
Viewvc Ubuntu upstream *

References