{ "CVE_data_meta" : { "ASSIGNER" : "cve@mitre.org", "ID" : "CVE-2007-3846", "STATE" : "PUBLIC" }, "affects" : { "vendor" : { "vendor_data" : [ { "product" : { "product_data" : [ { "product_name" : "n/a", "version" : { "version_data" : [ { "version_value" : "n/a" } ] } } ] }, "vendor_name" : "n/a" } ] } }, "data_format" : "MITRE", "data_type" : "CVE", "data_version" : "4.0", "description" : { "description_data" : [ { "lang" : "eng", "value" : "Directory traversal vulnerability in Subversion before 1.4.5, as used by TortoiseSVN before 1.4.5 and possibly other products, when run on Windows-based systems, allows remote authenticated users to overwrite and create arbitrary files via a ..\\ (dot dot backslash) sequence in the filename, as stored in the file repository." } ] }, "problemtype" : { "problemtype_data" : [ { "description" : [ { "lang" : "eng", "value" : "n/a" } ] } ] }, "references" : { "reference_data" : [ { "name" : "[users-subversion] 20070828 Subversion 1.4.5 releaded (Win32 security release)", "refsource" : "MLIST", "url" : "http://subversion.tigris.org/servlets/ReadMsg?list=users&msgNo=69413" }, { "name" : "http://crisp.cs.du.edu/?q=node/36", "refsource" : "MISC", "url" : "http://crisp.cs.du.edu/?q=node/36" }, { "name" : "http://subversion.tigris.org/servlets/NewsItemView?newsItemID=1941", "refsource" : "CONFIRM", "url" : "http://subversion.tigris.org/servlets/NewsItemView?newsItemID=1941" }, { "name" : "http://tortoisesvn.net/node/291", "refsource" : "CONFIRM", "url" : "http://tortoisesvn.net/node/291" }, { "name" : "http://subversion.tigris.org/servlets/ReadMsg?list=users&msgNo=69413", "refsource" : "CONFIRM", "url" : "http://subversion.tigris.org/servlets/ReadMsg?list=users&msgNo=69413" }, { "name" : "25468", "refsource" : "BID", "url" : "http://www.securityfocus.com/bid/25468" }, { "name" : "ADV-2007-3003", "refsource" : "VUPEN", "url" : "http://www.vupen.com/english/advisories/2007/3003" }, { "name" : "ADV-2007-3004", "refsource" : "VUPEN", "url" : "http://www.vupen.com/english/advisories/2007/3004" }, { "name" : "40118", "refsource" : "OSVDB", "url" : "http://osvdb.org/40118" }, { "name" : "40119", "refsource" : "OSVDB", "url" : "http://osvdb.org/40119" }, { "name" : "1018617", "refsource" : "SECTRACK", "url" : "http://securitytracker.com/id?1018617" }, { "name" : "26625", "refsource" : "SECUNIA", "url" : "http://secunia.com/advisories/26625" }, { "name" : "26632", "refsource" : "SECUNIA", "url" : "http://secunia.com/advisories/26632" }, { "name" : "subversion-filename-directory-traversal(36312)", "refsource" : "XF", "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/36312" } ] } }