[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2015-587 --- subversion mod_dav_svn

ID: oval:org.secpod.oval:def:1200095Date: (C)2016-01-04   (M)2023-12-07
Class: PATCHFamily: unix




The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service via a large number of REPORT requests, which trigger the traversal of FSFS repository nodes. An assertion failure flaw was found in the way the SVN server processed certain requests with dynamically evaluated revision numbers. A remote attacker could use this flaw to cause the SVN server to crash. It was found that the mod_dav_svn module did not properly validate the svn:author property of certain requests. An attacker able to create new revisions could use this flaw to spoof the svn:author property

Platform:
Amazon Linux AMI
Product:
subversion
mod_dav_svn
Reference:
ALAS-2015-587
CVE-2015-0202
CVE-2015-0248
CVE-2015-0251
CVE    3
CVE-2015-0248
CVE-2015-0202
CVE-2015-0251
CPE    67
cpe:/a:apache:subversion:1.6.10
cpe:/o:amazon:linux
cpe:/a:apache:subversion:1.6.11
cpe:/a:apache:subversion:1.6.12
...

© SecPod Technologies