PublicDate: 2008-03-24 17:44:00 UTC Candidate: CVE-2008-1291 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1291 Description: ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read files and list folders under the hidden CVSROOT folder. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_viewcvs: upstream_viewcvs: released (1.0.5) dapper_viewcvs: ignored (reached end-of-life) edgy_viewcvs: needed (reached end-of-life) feisty_viewcvs: needed (reached end-of-life) gutsy_viewcvs: DNE hardy_viewcvs: DNE intrepid_viewcvs: DNE jaunty_viewcvs: DNE karmic_viewcvs: DNE lucid_viewcvs: DNE maverick_viewcvs: DNE natty_viewcvs: DNE oneiric_viewcvs: DNE devel_viewcvs: DNE Patches_viewvc: upstream_viewvc: not-affected (1.0.5) dapper_viewvc: DNE edgy_viewvc: DNE feisty_viewvc: DNE gutsy_viewvc: needed (reached end-of-life) hardy_viewvc: ignored (reached end-of-life) intrepid_viewvc: not-affected (1.0.5-0.1) jaunty_viewvc: not-affected (1.0.5-0.2) karmic_viewvc: not-affected (1.0.5-0.2) lucid_viewvc: not-affected (1.0.9-1) maverick_viewvc: not-affected (1.0.9-1) natty_viewvc: not-affected (1.0.9-1) oneiric_viewvc: not-affected (1.0.9-1) devel_viewvc: not-affected (1.0.9-1)