CVE-2007-2448
Ubuntu Security Notice USN-1053-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit.
Subversion 1.4.3 y versiones anteriores no implementa apropiadamente el privilegio "acceso parcial" para usuarios que tienen acceso a rutas cambiadas pero no rutas copiadas, lo cual permite a usuarios remotos autenticados obtener información confidencial (propiedades de revisión) mediante svn (1) propget, (2) proplist, ó (3) propedit.
It was discovered that Subversion incorrectly handled certain 'partial access' privileges in rare scenarios. Remote authenticated users could use this flaw to obtain sensitive information (revision properties). This issue only applied to Ubuntu 6.06 LTS. It was discovered that the Subversion mod_dav_svn module for Apache did not properly handle a named repository as a rule scope. Remote authenticated users could use this flaw to bypass intended restrictions. This issue only applied to Ubuntu 9.10, 10.04 LTS, and 10.10. It was discovered that the Subversion mod_dav_svn module for Apache incorrectly handled the walk function. Remote authenticated users could use this flaw to cause the service to crash, leading to a denial of service. It was discovered that Subversion incorrectly handled certain memory operations. Remote authenticated users could use this flaw to consume large quantities of memory and cause the service to crash, leading to a denial of service. This issue only applied to Ubuntu 9.10, 10.04 LTS, and 10.10.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-05-02 CVE Reserved
- 2007-06-14 CVE Published
- 2024-08-07 CVE Updated
- 2025-07-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://osvdb.org/36070 | Vdb Entry | |
http://secunia.com/advisories/43139 | Third Party Advisory | |
http://subversion.tigris.org/security/CVE-2007-2448-advisory.txt | X_refsource_confirm | |
http://www.vupen.com/english/advisories/2007/2230 | Vdb Entry | |
http://www.vupen.com/english/advisories/2011/0264 | Vdb Entry | |
https://issues.rpath.com/browse/RPL-1896 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://securitytracker.com/id?1018237 | 2012-11-06 | |
http://www.securityfocus.com/bid/24463 | 2012-11-06 |
URL | Date | SRC |
---|---|---|
http://www.ubuntu.com/usn/USN-1053-1 | 2012-11-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Subversion Search vendor "Subversion" | Subversion Search vendor "Subversion" for product "Subversion" | <= 1.4.3 Search vendor "Subversion" for product "Subversion" and version " <= 1.4.3" | - |
Affected
|