Candidate: CVE-2012-3357 PublicDate: 2012-07-22 16:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3357 Description: The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is copied from an unreadable path, which allows remote attackers to obtain sensitive information, related to a "log msg leak." Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=679069 http://viewvc.tigris.org/issues/show_bug.cgi?id=353 Priority: low Discovered-by: Assigned-to: CVSS: Patches_viewvc: upstream: http://viewvc.tigris.org/source/browse/viewvc?view=rev&revision=2755 upstream: http://viewvc.tigris.org/source/browse/viewvc?view=rev&revision=2756 upstream: http://viewvc.tigris.org/source/browse/viewvc?view=rev&revision=2757 upstream: http://viewvc.tigris.org/source/browse/viewvc?view=rev&revision=2759 upstream: http://viewvc.tigris.org/source/browse/viewvc?view=rev&revision=2760 upstream_viewvc: released (1.1.5-1.1+squeeze1) hardy_viewvc: ignored (reached end-of-life) lucid_viewvc: ignored (reached end-of-life) natty_viewvc: ignored (reached end-of-life) oneiric_viewvc: ignored (reached end-of-life) precise_viewvc: released (1.1.5-1.1+squeeze2build0.12.04.1) quantal_viewvc: ignored (reached end-of-life) raring_viewvc: ignored (reached end-of-life) saucy_viewvc: ignored (reached end-of-life) trusty_viewvc: not-affected (1.1.5-1.4) trusty/esm_viewvc: DNE (trusty was not-affected [1.1.5-1.4]) utopic_viewvc: ignored (reached end-of-life) vivid_viewvc: ignored (reached end-of-life) vivid/stable-phone-overlay_viewvc: DNE vivid/ubuntu-core_viewvc: DNE wily_viewvc: ignored (reached end-of-life) xenial_viewvc: not-affected (1.1.22-1) yakkety_viewvc: not-affected (1.1.22-1) devel_viewvc: not-affected