# Local file exposure issue
Web:
https://groups.google.com/forum/?fromgroups=#!topic/sabredav-discuss/ehOUu7wTSGQ
## CVE IDENTIFIERS
- CVE-2013-1939
## AFFECTED SOFTWARE
- SabreDAV < 1.6.8, < 1.7.6, < 1.8.4 running in Windows hosts.
## DESCRIPTION
It was possible for authenticated users on to read any file on the local
filesystem, accessible by the webserver.
Thanks to Lukas Reschke for reporting this issue.
## RESOLUTION
Update to SabreDAV 1.6.9, 1.7.7 or 1.8.5 or turn off the 'Browser plugin'.
Zipballs:
http://code.google.com/p/sabredav/downloads/list
Or with composer:
composer update sabre/dav
Regards,
Evert Pot
//The information contained within this publication is
//supplied "as-is"with no warranties or guarantees of fitness
//of use or otherwise. Bot24, Inc nor Bradley Sean Susser accepts
//responsibility for any damage caused by the use or misuse of
//this information