CVE-2010-0004
EUVD-2010-003629.01.2010, 18:30
ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discover private root names by reading this view.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| viewvc | viewvc | 1.0.1 |
| viewvc | viewvc | 1.0.2 |
| viewvc | viewvc | 1.0.3 |
| viewvc | viewvc | 1.0.4 |
| viewvc | viewvc | 1.0.5 |
| viewvc | viewvc | 1.0.6 |
| viewvc | viewvc | 1.0.7 |
| viewvc | viewvc | 1.0.8 |
| viewvc | viewvc | 1.1.0 |
| viewvc | viewvc | 1.1.1 |
| viewvc | viewvc | 1.1.2 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References