Oval Definition:oval:com.redhat.rhsa:def:20091203
Revision Date:2009-08-10Version:645
Title:RHSA-2009:1203: subversion security update (Important)
Description:Subversion (SVN) is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes.

  • Matt Lewis, of Google, reported multiple heap overflow flaws in Subversion (server and client) when parsing binary deltas. A malicious user with commit access to a server could use these flaws to cause a heap overflow on that server. A malicious server could use these flaws to cause a heap overflow on a client when it attempts to checkout or update. These heap overflows can result in a crash or, possibly, arbitrary code execution. (CVE-2009-2411)

    All Subversion users should upgrade to these updated packages, which contain a backported patch to correct these issues. After installing the updated packages, the Subversion server must be restarted for the update to take effect: restart httpd if you are using mod_dav_svn, or restart svnserve if it is used.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-2411
    RHSA-2009:1203
    RHSA-2009:1203-01
    RHSA-2009:1203-01
    Platform(s):Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • mod_dav_svn is earlier than 0:1.1.4-3.el4_8.2
  • AND mod_dav_svn is signed with Red Hat redhatrelease2 key
  • subversion is earlier than 0:1.1.4-3.el4_8.2
  • AND subversion is signed with Red Hat redhatrelease2 key
  • subversion-devel is earlier than 0:1.1.4-3.el4_8.2
  • AND subversion-devel is signed with Red Hat redhatrelease2 key
  • subversion-perl is earlier than 0:1.1.4-3.el4_8.2
  • AND subversion-perl is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • mod_dav_svn is earlier than 0:1.4.2-4.el5_3.1
  • AND mod_dav_svn is signed with Red Hat redhatrelease2 key
  • subversion is earlier than 0:1.4.2-4.el5_3.1
  • AND subversion is signed with Red Hat redhatrelease2 key
  • subversion-devel is earlier than 0:1.4.2-4.el5_3.1
  • AND subversion-devel is signed with Red Hat redhatrelease2 key
  • subversion-javahl is earlier than 0:1.4.2-4.el5_3.1
  • AND subversion-javahl is signed with Red Hat redhatrelease2 key
  • subversion-perl is earlier than 0:1.4.2-4.el5_3.1
  • AND subversion-perl is signed with Red Hat redhatrelease2 key
  • subversion-ruby is earlier than 0:1.4.2-4.el5_3.1
  • AND subversion-ruby is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • mod_dav_svn is earlier than 0:1.1.4-3.el4_8.2
  • AND mod_dav_svn is signed with Red Hat master key
  • subversion is earlier than 0:1.1.4-3.el4_8.2
  • AND subversion is signed with Red Hat master key
  • subversion-devel is earlier than 0:1.1.4-3.el4_8.2
  • AND subversion-devel is signed with Red Hat master key
  • subversion-perl is earlier than 0:1.1.4-3.el4_8.2
  • AND subversion-perl is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • mod_dav_svn is earlier than 0:1.4.2-4.el5_3.1
  • AND mod_dav_svn is signed with Red Hat redhatrelease key
  • subversion is earlier than 0:1.4.2-4.el5_3.1
  • AND subversion is signed with Red Hat redhatrelease key
  • subversion-devel is earlier than 0:1.4.2-4.el5_3.1
  • AND subversion-devel is signed with Red Hat redhatrelease key
  • subversion-javahl is earlier than 0:1.4.2-4.el5_3.1
  • AND subversion-javahl is signed with Red Hat redhatrelease key
  • subversion-perl is earlier than 0:1.4.2-4.el5_3.1
  • AND subversion-perl is signed with Red Hat redhatrelease key
  • subversion-ruby is earlier than 0:1.4.2-4.el5_3.1
  • AND subversion-ruby is signed with Red Hat redhatrelease key
  • BACK