Candidate: CVE-2009-0240 PublicDate: 2009-01-21 02:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0240 Description: listing.php in WebSVN 2.0 and possibly 1.7 beta, when using an SVN authz file, allows remote authenticated users to read changelogs or diffs for restricted projects via a modified repname parameter. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_websvn: upstream_websvn: released (2.0-4+lenny1, 2.1.0-1) dapper_websvn: ignored (reached end-of-life) gutsy_websvn: needed (reached end-of-life) hardy_websvn: ignored (reached end-of-life) intrepid_websvn: needed (reached end-of-life) jaunty_websvn: not-affected (2.0-4+lenny1) karmic_websvn: not-affected (2.2.1-1) lucid_websvn: not-affected maverick_websvn: not-affected natty_websvn: not-affected oneiric_websvn: not-affected devel_websvn: not-affected