CVE-2004-1438

NameCVE-2004-1438
DescriptionThe mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repository via the svn copy command.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
subversion (PTS)bullseye1.14.1-3+deb11u1fixed
bullseye (security)1.14.1-3+deb11u2fixed
bookworm1.14.2-4+deb12u1fixed
trixie1.14.5-3fixed
forky, sid1.14.5-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
subversionsource(unstable)1.0.6-1

Search for package or bug name: Reporting problems