Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2016:1511-1

Опубликовано: 07 июн. 2016
Источник: suse-cvrf

Описание

Security update for subversion

This update for subversion fixes the following issues:

  • CVE-2015-3187: svn_repos_trace_node_locations() reveals paths hidden by authz (bsc#939517)
  • CVE-2016-2167: mod_authz_svn: DoS in MOVE/COPY authorization check (bsc#976849)
  • CVE-2016-2168: svnserve/sasl may authenticate users using the wrong realm (bsc#976850)

Список пакетов

SUSE Linux Enterprise Software Development Kit 11 SP4
subversion-1.6.17-1.35.1
subversion-devel-1.6.17-1.35.1
subversion-perl-1.6.17-1.35.1
subversion-python-1.6.17-1.35.1
subversion-server-1.6.17-1.35.1
subversion-tools-1.6.17-1.35.1
SUSE Studio Onsite 1.3
subversion-1.6.17-1.35.1

Описание

The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has been moved from a hidden path.


Затронутые продукты
SUSE Linux Enterprise Software Development Kit 11 SP4:subversion-1.6.17-1.35.1
SUSE Linux Enterprise Software Development Kit 11 SP4:subversion-devel-1.6.17-1.35.1
SUSE Linux Enterprise Software Development Kit 11 SP4:subversion-perl-1.6.17-1.35.1
SUSE Linux Enterprise Software Development Kit 11 SP4:subversion-python-1.6.17-1.35.1

Ссылки

Описание

The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm string that is a prefix of an expected repository realm string.


Затронутые продукты
SUSE Linux Enterprise Software Development Kit 11 SP4:subversion-1.6.17-1.35.1
SUSE Linux Enterprise Software Development Kit 11 SP4:subversion-devel-1.6.17-1.35.1
SUSE Linux Enterprise Software Development Kit 11 SP4:subversion-perl-1.6.17-1.35.1
SUSE Linux Enterprise Software Development Kit 11 SP4:subversion-python-1.6.17-1.35.1

Ссылки

Описание

The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a crafted header in a (1) MOVE or (2) COPY request, involving an authorization check.


Затронутые продукты
SUSE Linux Enterprise Software Development Kit 11 SP4:subversion-1.6.17-1.35.1
SUSE Linux Enterprise Software Development Kit 11 SP4:subversion-devel-1.6.17-1.35.1
SUSE Linux Enterprise Software Development Kit 11 SP4:subversion-perl-1.6.17-1.35.1
SUSE Linux Enterprise Software Development Kit 11 SP4:subversion-python-1.6.17-1.35.1

Ссылки