Vulnerability Bulletins |
DSA-3137 websvn - security update |
|
| Affected software | Debian |
|
James Clawson discovered that websvn, a web viewer for Subversionrepositories, would follow symlinks in a repository when presenting afile for download. An attacker with repository write access couldthereby access any file on disk readable by the user the webserverruns as. More info: https://www.debian.org/security/2015/dsa-3137 |
|






