Vulnerability Bulletins

DSA-3137 websvn - security update

   
Affected software Debian
 
James Clawson discovered that websvn, a web viewer for Subversionrepositories, would follow symlinks in a repository when presenting afile for download. An attacker with repository write access couldthereby access any file on disk readable by the user the webserverruns as.

More info:

https://www.debian.org/security/2015/dsa-3137