[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2011:0258-01 -- Redhat subversion

ID: oval:org.secpod.oval:def:500281Date: (C)2012-01-31   (M)2023-02-20
Class: PATCHFamily: unix




Subversion is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes. The mod_dav_svn module is used with the Apache HTTP Server to allow access to Subversion repositories via HTTP. An access restriction bypass flaw was found in the mod_dav_svn module. If the SVNPathAuthz directive was set to "short_circuit", certain access rules were not enforced, possibly allowing sensitive repository data to be leaked to remote users. Note that SVNPathAuthz is set to "On" by default. A server-side memory leak was found in the Subversion server. If a malicious, remote user performed "svn blame" or "svn log" operations on certain repository files, it could cause the Subversion server to consume a large amount of system memory. A NULL pointer dereference flaw was found in the way the mod_dav_svn module processed certain requests. If a malicious, remote user issued a certain type of request to display a collection of Subversion repositories on a host that has the SVNListParentPath directive enabled, it could cause the httpd process serving the request to crash. Note that SVNListParentPath is not enabled by default. All Subversion users should upgrade to these updated packages, which contain backported patches to correct these issues. After installing the updated packages, the Subversion server must be restarted for the update to take effect: restart httpd if you are using mod_dav_svn, or restart svnserve if it is used.

Platform:
Red Hat Enterprise Linux 6
Product:
subversion
Reference:
RHSA-2011:0258-01
CVE-2010-3315
CVE-2010-4539
CVE-2010-4644
CVE    3
CVE-2010-4539
CVE-2010-4644
CVE-2010-3315
CPE    112
cpe:/a:apache:subversion:0.21.0
cpe:/a:apache:subversion:0.25.0
cpe:/a:apache:subversion:0.6
cpe:/a:apache:subversion:0.7
...

© SecPod Technologies