Subversion alert on Fedora
Fedora alert FEDORA-2011-8352 (subversion)
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 |
<pre> <table> <tbody> <tr> <td valign="top"><strong>From</strong>:</td> <td></td> <td valign="top">updates@fedoraproject.org</td> </tr> <tr> <td valign="top"><strong>To</strong>:</td> <td></td> <td valign="top">package-announce@lists.fedoraproject.org</td> </tr> <tr> <td valign="top"><strong>Subject</strong>:</td> <td></td> <td valign="top">[SECURITY] Fedora 15 Update: subversion-1.6.17-1.fc15</td> </tr> <tr> <td valign="top"><strong>Date</strong>:</td> <td></td> <td valign="top">Fri, 24 Jun 2011 03:49:12 +0000</td> </tr> <tr> <td valign="top"><strong>Message-ID</strong>:</td> <td></td> <td valign="top"><20110624034912.933C61101D2@bastion02.phx2.fedoraproject.org></td> </tr> <tr> <td valign="top"></td> <td></td> <td valign="top"></td> </tr> </tbody> </table> -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2011-8352 2011-06-15 17:46:08 -------------------------------------------------------------------------------- Name : subversion Product : Fedora 15 Version : 1.6.17 Release : 1.fc15 URL : <a href="http://subversion.apache.org/">http://subversion.apache.org/</a> Summary : A Modern Concurrent Version Control System Description : Subversion is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes. Subversion only stores the differences between versions, instead of every complete file. Subversion is intended to be a compelling replacement for CVS. -------------------------------------------------------------------------------- Update Information: This update includes the latest release of Subversion, fixing three security issues: An infinite loop flaw was found in the way the mod_dav_svn module processed certain data sets. If the SVNPathAuthz directive was set to "short_circuit", and path-based access control for files and directories was enabled, a malicious, remote user could use this flaw to cause the httpd process serving the request to consume an excessive amount of system memory. (CVE-2011-1783) A NULL pointer dereference flaw was found in the way the mod_dav_svn module processed requests submitted against the URL of a baselined resource. A malicious, remote user could use this flaw to cause the httpd process serving the request to crash. (CVE-2011-1752) An information disclosure flaw was found in the way the mod_dav_svn module processed certain URLs when path-based access control for files and directories was enabled. A malicious, remote user could possibly use this flaw to access certain files in a repository that would otherwise not be accessible to them. Note: This vulnerability cannot be triggered if the SVNPathAuthz directive is set to "short_circuit". (CVE-2011-1921) The Fedora Project would like to thank the Apache Subversion project for reporting these issues. Upstream acknowledges Joe Schaefer of the Apache Software Foundation as the original reporter of CVE-2011-1752; Ivan Zhakov of VisualSVN as the original reporter of CVE-2011-1783; and Kamesh Jayachandran of CollabNet, Inc. as the original reporter of CVE-2011-1921. The following bugs are also fixed in this release: * make 'blame -g' more efficient on with large mergeinfo * preserve log message with a non-zero editor exit * fix FSFS cache performance on 64-bit platforms * make svn cleanup tolerate obstructed directories * fix deadlock in multithreaded servers serving FSFS repositories * detect very occasional corruption and abort commit * fixed: file externals cause non-inheritable mergeinfo * fixed: file externals cause mixed-revision working copies * fixed: write-through proxy could direcly commit to slave * detect a particular corruption condition in FSFS * improve error message when clients refer to unkown revisions * bugfixes and optimizations to the DAV mirroring code * fixed: locked and deleted file causes tree conflict * fixed: update touches locked file with svn:keywords property * fix svnsync handling of directory copyfrom * fix 'log -g' excessive duplicate output * fix svnsync copyfrom handling bug with BDB * server-side validation of svn:mergeinfo syntax during commit -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 2 2011 Joe Orton <jorton@redhat.com> - 1.6.17-1 - update to 1.6.17 (#709952) -------------------------------------------------------------------------------- References: [ 1 ] Bug #709952 - CVE-2011-1752 CVE-2011-1783 CVE-2011-1921 subversion various flaws [fedora-all] <a href="https://bugzilla.redhat.com/show_bug.cgi?id=709952">https://bugzilla.redhat.com/show_bug.cgi?id=709952</a> -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update subversion' at the command line. For more information, refer to "Managing Software with yum", available at <a href="http://docs.fedoraproject.org/yum/">http://docs.fedoraproject.org/yum/</a>. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at <a href="https://fedoraproject.org/keys">https://fedoraproject.org/keys</a> -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org <a href="https://admin.fedoraproject.org/mailman/listinfo/package-announce">https://admin.fedoraproject.org/mailman/listinfo/package-...</a> Fonte: <a href="http://lwn.net/Articles/449148/">http://lwn.net/Articles/449148/</a> |