{
  "threat_severity" : "Low",
  "public_date" : "2007-11-06T00:00:00Z",
  "bugzilla" : {
    "description" : "subversion: revision properties disclosure to user with partial access",
    "id" : "243757",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=243757"
  },
  "cvss" : {
    "cvss_base_score" : "1.5",
    "cvss_scoring_vector" : "AV:L/AC:M/Au:S/C:P/I:N/A:N",
    "status" : "verified"
  },
  "details" : [ "Subversion 1.4.3 and earlier does not properly implement the \"partial access\" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit." ],
  "statement" : "The Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2011-01-13T00:00:00Z",
    "advisory" : "RHEA-2011:0039",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "subversion-0:1.6.11-7.el5"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 4",
    "fix_state" : "Will not fix",
    "package_name" : "subversion",
    "cpe" : "cpe:/o:redhat:enterprise_linux:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2007-2448\nhttps://nvd.nist.gov/vuln/detail/CVE-2007-2448" ],
  "name" : "CVE-2007-2448",
  "csaw" : false
}