Skip to content
AppUnix

Subversion alert on Fedora

24/06/2011 by OwnServer

Fedora alert FEDORA-2011-8352 (subversion)

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
<pre>
<table>
<tbody>
<tr>
<td valign="top"><strong>From</strong>:</td>
<td></td>
<td valign="top">updates@fedoraproject.org</td>
</tr>
<tr>
<td valign="top"><strong>To</strong>:</td>
<td></td>
<td valign="top">package-announce@lists.fedoraproject.org</td>
</tr>
<tr>
<td valign="top"><strong>Subject</strong>:</td>
<td></td>
<td valign="top">[SECURITY] Fedora 15 Update: subversion-1.6.17-1.fc15</td>
</tr>
<tr>
<td valign="top"><strong>Date</strong>:</td>
<td></td>
<td valign="top">Fri, 24 Jun 2011 03:49:12 +0000</td>
</tr>
<tr>
<td valign="top"><strong>Message-ID</strong>:</td>
<td></td>
<td valign="top">&lt;20110624034912.933C61101D2@bastion02.phx2.fedoraproject.org&gt;</td>
</tr>
<tr>
<td valign="top"></td>
<td></td>
<td valign="top"></td>
</tr>
</tbody>
</table>
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-8352
2011-06-15 17:46:08
--------------------------------------------------------------------------------
 
Name        : subversion
Product     : Fedora 15
Version     : 1.6.17
Release     : 1.fc15
URL         : <a href="http://subversion.apache.org/">http://subversion.apache.org/</a>
Summary     : A Modern Concurrent Version Control System
Description :
Subversion is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a
hierarchy of files and directories while keeping a history of all
changes.  Subversion only stores the differences between versions,
instead of every complete file.  Subversion is intended to be a
compelling replacement for CVS.
 
--------------------------------------------------------------------------------
Update Information:
 
This update includes the latest release of Subversion, fixing three security issues:
 
An infinite loop flaw was found in the way the mod_dav_svn module processed certain data sets. If
the SVNPathAuthz directive was set to "short_circuit", and path-based access control for files and
directories was enabled, a malicious, remote user could use this flaw to cause the httpd process
serving the request to consume an excessive amount of system memory. (CVE-2011-1783)
 
A NULL pointer dereference flaw was found in the way the mod_dav_svn module processed requests
submitted against the URL of a baselined resource. A malicious, remote user could use this flaw to
cause the httpd process serving the request to crash. (CVE-2011-1752)
 
An information disclosure flaw was found in the way the mod_dav_svn
module processed certain URLs when path-based access control for files and directories was enabled.
A malicious, remote user could possibly use this flaw to access certain files in a repository that
would otherwise not be accessible to them. Note: This vulnerability cannot be triggered if the
SVNPathAuthz directive is set to "short_circuit". (CVE-2011-1921)
 
The Fedora Project would like to thank the Apache Subversion project for reporting these issues.
Upstream acknowledges Joe Schaefer of the Apache Software Foundation as the original reporter of
CVE-2011-1752; Ivan Zhakov of VisualSVN as the original reporter of CVE-2011-1783; and Kamesh
Jayachandran of CollabNet, Inc. as the original reporter of CVE-2011-1921.
 
The following bugs are also fixed in this release:
 
* make 'blame -g' more efficient on with large mergeinfo
* preserve log message with a non-zero editor exit
* fix FSFS cache performance on 64-bit platforms
* make svn cleanup tolerate obstructed directories
* fix deadlock in multithreaded servers serving FSFS repositories
* detect very occasional corruption and abort commit
* fixed: file externals cause non-inheritable mergeinfo
* fixed: file externals cause mixed-revision working copies
* fixed: write-through proxy could direcly commit to slave
* detect a particular corruption condition in FSFS
* improve error message when clients refer to unkown revisions
* bugfixes and optimizations to the DAV mirroring code
* fixed: locked and deleted file causes tree conflict
* fixed: update touches locked file with svn:keywords property
* fix svnsync handling of directory copyfrom
* fix 'log -g' excessive duplicate output
* fix svnsync copyfrom handling bug with BDB
* server-side validation of svn:mergeinfo syntax during commit
--------------------------------------------------------------------------------
ChangeLog:
 
* Thu Jun  2 2011 Joe Orton &lt;jorton@redhat.com&gt; - 1.6.17-1
- update to 1.6.17 (#709952)
--------------------------------------------------------------------------------
References:
 
  [ 1 ] Bug #709952 - CVE-2011-1752 CVE-2011-1783 CVE-2011-1921 subversion various flaws
[fedora-all]
        <a href="https://bugzilla.redhat.com/show_bug.cgi?id=709952">https://bugzilla.redhat.com/show_bug.cgi?id=709952</a>
--------------------------------------------------------------------------------
 
This update can be installed with the "yum" update program.  Use
su -c 'yum update subversion' at the command line.
For more information, refer to "Managing Software with yum",
available at <a href="http://docs.fedoraproject.org/yum/">http://docs.fedoraproject.org/yum/</a>.
 
All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
<a href="https://fedoraproject.org/keys">https://fedoraproject.org/keys</a>
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
<a href="https://admin.fedoraproject.org/mailman/listinfo/package-announce">https://admin.fedoraproject.org/mailman/listinfo/package-...</a>
 
Fonte: <a href="http://lwn.net/Articles/449148/">http://lwn.net/Articles/449148/</a>

Post navigation

Previous Post:

Vulnerabilidade do Opera Browser no Opensuse 11.x

Next Post:

Ubuntu alert USN-1158-1 (curl) CURL vulnerabilidade

Pesquisa

Categorias

  • Blog
  • cPanel
  • How Tos
  • Linux
  • Mac Os
  • MySQL
  • Wordpress

#Apoiadores

Patrocinador

Registre-se e ganhe $25



© 2022 AppUnix | Built using WordPress and MxGuard