Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:4591

Опубликовано: 18 мая 2022
Источник: rocky
Оценка: Important

Описание

Important: subversion security update

Subversion (SVN) is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes.

Security Fix(es):

  • subversion: Subversion's mod_dav_svn is vulnerable to memory corruption (CVE-2022-24070)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
mod_dav_svnx86_645.el9_0mod_dav_svn-1.14.1-5.el9_0.x86_64.rpm
python3-subversionx86_645.el9_0python3-subversion-1.14.1-5.el9_0.x86_64.rpm
subversionx86_645.el9_0subversion-1.14.1-5.el9_0.x86_64.rpm
subversion-develx86_645.el9_0subversion-devel-1.14.1-5.el9_0.x86_64.rpm
subversion-gnomex86_645.el9_0subversion-gnome-1.14.1-5.el9_0.x86_64.rpm
subversion-libsx86_645.el9_0subversion-libs-1.14.1-5.el9_0.x86_64.rpm
subversion-perlx86_645.el9_0subversion-perl-1.14.1-5.el9_0.x86_64.rpm
subversion-toolsx86_645.el9_0subversion-tools-1.14.1-5.el9_0.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do not use mod_dav_svn are not affected.

CVSS3: 7.5
redhat
почти 4 года назад

Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do not use mod_dav_svn are not affected.

CVSS3: 7.5
nvd
больше 3 лет назад

Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do not use mod_dav_svn are not affected.

CVSS3: 7.5
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 3 лет назад

Subversion's mod_dav_svn is vulnerable to memory corruption. While loo ...