Quantcast
Channel: BOT24
Viewing all articles
Browse latest Browse all 8064

SabreDAV security advisory (CVE-2013-1939)

$
0
0

# Local file exposure issue
Web:
https://groups.google.com/forum/?fromgroups=#!topic/sabredav-discuss/ehOUu7wTSGQ


## CVE IDENTIFIERS
- CVE-2013-1939

## AFFECTED SOFTWARE
- SabreDAV < 1.6.8, < 1.7.6, < 1.8.4 running in Windows hosts.

## DESCRIPTION

It was possible for authenticated users on to read any file on the local
filesystem, accessible by the webserver.

Thanks to Lukas Reschke for reporting this issue.

## RESOLUTION
Update to SabreDAV 1.6.9, 1.7.7 or 1.8.5 or turn off the 'Browser plugin'.

Zipballs:
http://code.google.com/p/sabredav/downloads/list

Or with composer:
composer update sabre/dav

Regards,
Evert Pot



//The information contained within this publication is





//supplied "as-is"with no warranties or guarantees of fitness





//of use or otherwise. Bot24, Inc nor Bradley Sean Susser accepts





//responsibility for any damage caused by the use or misuse of





//this information



Viewing all articles
Browse latest Browse all 8064

Trending Articles