CVE-2007-2448

Source
https://nvd.nist.gov/vuln/detail/CVE-2007-2448
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2007-2448.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2007-2448
Related
Published
2007-06-14T23:30:00Z
Modified
2024-06-30T12:01:22Z
Summary
[none]
Details

Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit.

References

Affected packages

Debian:11 / subversion

Package

Name
subversion
Purl
pkg:deb/debian/subversion?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.4dfsg1-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:12 / subversion

Package

Name
subversion
Purl
pkg:deb/debian/subversion?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.4dfsg1-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:13 / subversion

Package

Name
subversion
Purl
pkg:deb/debian/subversion?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.4dfsg1-1

Ecosystem specific

{
    "urgency": "low"
}