Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:0776-1

Опубликовано: 02 апр. 2015
Источник: suse-cvrf

Описание

Security update for subversion

Apache Subversion was updated to fix three vulnerabilities.

The following vulnerabilities were fixed:

  • Subversion HTTP servers with FSFS repositories were vulnerable to a remotely triggerable excessive memory use with certain REPORT requests. (bsc#923793 CVE-2015-0202)
  • Subversion mod_dav_svn and svnserve were vulnerable to a remotely triggerable assertion DoS vulnerability for certain requests with dynamically evaluated revision numbers. (bsc#923794 CVE-2015-0248)
  • Subversion HTTP servers allow spoofing svn:author property values for new revisions (bsc#923795 CVE-2015-0251)

Список пакетов

SUSE Linux Enterprise Software Development Kit 12
libsvn_auth_gnome_keyring-1-0-1.8.10-12.1
libsvn_auth_kwallet-1-0-1.8.10-12.1
subversion-1.8.10-12.1
subversion-bash-completion-1.8.10-12.1
subversion-devel-1.8.10-12.1
subversion-perl-1.8.10-12.1
subversion-python-1.8.10-12.1
subversion-server-1.8.10-12.1
subversion-tools-1.8.10-12.1

Описание

The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large number of REPORT requests, which trigger the traversal of FSFS repository nodes.


Затронутые продукты
SUSE Linux Enterprise Software Development Kit 12:libsvn_auth_gnome_keyring-1-0-1.8.10-12.1
SUSE Linux Enterprise Software Development Kit 12:libsvn_auth_kwallet-1-0-1.8.10-12.1
SUSE Linux Enterprise Software Development Kit 12:subversion-1.8.10-12.1
SUSE Linux Enterprise Software Development Kit 12:subversion-bash-completion-1.8.10-12.1

Ссылки

Описание

The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and abort) via crafted parameter combinations related to dynamically evaluated revision numbers.


Затронутые продукты
SUSE Linux Enterprise Software Development Kit 12:libsvn_auth_gnome_keyring-1-0-1.8.10-12.1
SUSE Linux Enterprise Software Development Kit 12:libsvn_auth_kwallet-1-0-1.8.10-12.1
SUSE Linux Enterprise Software Development Kit 12:subversion-1.8.10-12.1
SUSE Linux Enterprise Software Development Kit 12:subversion-bash-completion-1.8.10-12.1

Ссылки

Описание

The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.


Затронутые продукты
SUSE Linux Enterprise Software Development Kit 12:libsvn_auth_gnome_keyring-1-0-1.8.10-12.1
SUSE Linux Enterprise Software Development Kit 12:libsvn_auth_kwallet-1-0-1.8.10-12.1
SUSE Linux Enterprise Software Development Kit 12:subversion-1.8.10-12.1
SUSE Linux Enterprise Software Development Kit 12:subversion-bash-completion-1.8.10-12.1

Ссылки