Processed: Re: Bug#416696: viewvc: Forbids only directories, not files

2007-03-30 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > severity 416696 important Bug#416696: viewvc: Forbids only directories, not files Severity set to `important' from `critical' > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking syst

Bug#416696: viewvc: Forbids only directories, not files

2007-03-30 Thread David Martínez Moreno
severity 416696 important thanks El jueves, 29 de marzo de 2007 22:17, Chung-chieh Shan escribió: > Package: viewvc > Version: 1.0.3-2 > Severity: critical > Tags: security patch > Justification: causes serious data loss > > Hello, > > viewvc provides a "forbidden" configuration option to forbid a

Bug#416696: viewvc: Forbids only directories, not files

2007-03-29 Thread Chung-chieh Shan
Package: viewvc Version: 1.0.3-2 Severity: critical Tags: security patch Justification: causes serious data loss Hello, viewvc provides a "forbidden" configuration option to forbid access to parts of a repository, but only *directory* listing is forbidden. An attacker who guesses a file name can