Unrated severityNVD Advisory· Published Sep 30, 2008· Updated Apr 23, 2026
CVE-2008-4325
CVE-2008-4325
Description
lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which allows remote attackers to cause content to be misinterpreted by the browser via a content-type parameter that is inconsistent with the requested object. NOTE: this issue might not be a vulnerability, since it requires attacker access to the repository that is being viewed.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- viewvc.tigris.org/issues/show_bug.cginvdPatch
- viewvc.tigris.org/source/browse/viewvc/trunk/lib/viewvc.pynvd
- viewvc.tigris.org/source/browse/viewvcnvd
- www.openwall.com/lists/oss-security/2008/09/19/4nvd
- www.openwall.com/lists/oss-security/2008/09/20/1nvd
- www.redhat.com/archives/fedora-package-announce/2008-September/msg01101.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2008-September/msg01142.htmlnvd
News mentions
0No linked articles in our index yet.