~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2013-7301

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2013-7301
2
 
PublicDate: 2014-02-01
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7301
5
 
 https://code.google.com/p/cantata/issues/detail?id=356
6
 
Description:
7
 
 Cantata before 1.2.2 does not restrict access to files in the play queue,
8
 
 which allows remote attackers to obtain sensitive information by reading
9
 
 the songs in the queue.
10
 
Ubuntu-Description:
11
 
 Automatically started HTTP server listens on all interfaces and will serve
12
 
 any file that the user running the HTTP server has access to, including e.g.
13
 
 ssh private keys.
14
 
Notes:
15
 
 sbeattie> according to debian bug report, 1.1.3 package does not start
16
 
   httpd server by default
17
 
Bugs:
18
 
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=736154
19
 
Priority: medium
20
 
Discovered-by:
21
 
Assigned-to:
22
 
 
23
 
Patches_cantata:
24
 
upstream_cantata: pending (1.2.2)
25
 
lucid_cantata: DNE
26
 
precise_cantata: DNE
27
 
quantal_cantata: DNE
28
 
raring_cantata: ignored (reached end-of-life)
29
 
saucy_cantata: ignored (reached end-of-life)
30
 
trusty_cantata: not-affected (1.1.3-0ubuntu1~ubuntu13.11)
31
 
devel_cantata: not-affected (1.3.4.ds1-1)