viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://security-tracker.debian.org/tracker/CVE-2007-5743 | third party advisory |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=416696 | third party advisory issue tracking exploit |