[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2011:0257 -- centos 5 i386 subversion

ID: oval:org.secpod.oval:def:201491Date: (C)2012-01-31   (M)2023-02-20
Class: PATCHFamily: unix




Subversion is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes. A server-side memory leak was found in the Subversion server. If a malicious, remote user performed "svn blame" or "svn log" operations on certain repository files, it could cause the Subversion server to consume a large amount of system memory. A NULL pointer dereference flaw was found in the way the mod_dav_svn module processed certain requests. If a malicious, remote user issued a certain type of request to display a collection of Subversion repositories on a host that has the SVNListParentPath directive enabled, it could cause the httpd process serving the request to crash. Note that SVNListParentPath is not enabled by default. All Subversion users should upgrade to these updated packages, which contain backported patches to correct these issues. After installing the updated packages, the Subversion server must be restarted for the update to take effect: restart httpd if you are using mod_dav_svn, or restart svnserve if it is used.

Platform:
CentOS 5
Product:
subversion
Reference:
CESA-2011:0257
CVE-2010-4539
CVE-2010-4644
CVE    2
CVE-2010-4539
CVE-2010-4644
CPE    112
cpe:/a:apache:subversion:0.21.0
cpe:/a:apache:subversion:0.25.0
cpe:/a:apache:subversion:0.6
cpe:/a:apache:subversion:0.7
...

© SecPod Technologies