Oval Definition:oval:com.redhat.rhsa:def:20172480
Revision Date:2017-08-15Version:636
Title:RHSA-2017:2480: subversion security update (Important)
Description:Subversion (SVN) is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes.

Security Fix(es):

  • A shell command injection flaw related to the handling of "svn+ssh" URLs has been discovered in Subversion. An attacker could use this flaw to execute shell commands with the privileges of the user running the Subversion client, for example when performing a "checkout" or "update" action on a malicious repository, or a legitimate repository containing a malicious commit. (CVE-2017-9800)

    Red Hat would like to thank the Subversion Team for reporting this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2017-9800
    RHSA-2017:2480
    RHSA-2017:2480-00
    RHSA-2017:2480-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • mod_dav_svn is earlier than 0:1.7.14-11.el7_4
  • AND mod_dav_svn is signed with Red Hat redhatrelease2 key
  • subversion is earlier than 0:1.7.14-11.el7_4
  • AND subversion is signed with Red Hat redhatrelease2 key
  • subversion-devel is earlier than 0:1.7.14-11.el7_4
  • AND subversion-devel is signed with Red Hat redhatrelease2 key
  • subversion-gnome is earlier than 0:1.7.14-11.el7_4
  • AND subversion-gnome is signed with Red Hat redhatrelease2 key
  • subversion-javahl is earlier than 0:1.7.14-11.el7_4
  • AND subversion-javahl is signed with Red Hat redhatrelease2 key
  • subversion-kde is earlier than 0:1.7.14-11.el7_4
  • AND subversion-kde is signed with Red Hat redhatrelease2 key
  • subversion-libs is earlier than 0:1.7.14-11.el7_4
  • AND subversion-libs is signed with Red Hat redhatrelease2 key
  • subversion-perl is earlier than 0:1.7.14-11.el7_4
  • AND subversion-perl is signed with Red Hat redhatrelease2 key
  • subversion-python is earlier than 0:1.7.14-11.el7_4
  • AND subversion-python is signed with Red Hat redhatrelease2 key
  • subversion-ruby is earlier than 0:1.7.14-11.el7_4
  • AND subversion-ruby is signed with Red Hat redhatrelease2 key
  • subversion-tools is earlier than 0:1.7.14-11.el7_4
  • AND subversion-tools is signed with Red Hat redhatrelease2 key
  • BACK