PublicDateAtUSN: 2011-06-02 Candidate: CVE-2011-1921 PublicDate: 2011-06-06 19:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1921 http://subversion.apache.org/security/CVE-2011-1921-advisory.txt https://ubuntu.com/security/notices/USN-1144-1 Description: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Kamesh Jayachandran Assigned-to: mdeslaur CVSS: Patches_subversion: upstream: http://svn.apache.org/viewvc?view=revision&revision=1130303 upstream_subversion: released (1.6.17) hardy_subversion: ignored (reached end-of-life) lucid_subversion: released (1.6.6dfsg-2ubuntu1.3) maverick_subversion: released (1.6.12dfsg-1ubuntu1.3) natty_subversion: released (1.6.12dfsg-4ubuntu2.1) devel_subversion: released (1.6.12dfsg-4ubuntu5)