Oval Definition:oval:org.mitre.oval:def:11774
Revision Date:2014-06-23Version:20
Title:DSA-2118-1 subversion -- logic flaw
Description:Kamesh Jayachandran and C. Michael Pilat discovered that the mod_dav_svn module of subversion, a version control system, is not properly enforcing access rules which are scope-limited to named repositories. If the SVNPathAuthz option is set to "short_circuit" set this may enable an unprivileged attacker to bypass intended access restrictions and disclose or modify repository content. As a workaround it is also possible to set SVNPathAuthz to "on" but be advised that this can result in a performance decrease for large repositories. For the stable distribution, this problem has been fixed in version 1.5.1dfsg1-5. For the testing distribution, this problem has been fixed in version 1.6.12dfsg-2. For the unstable distribution, this problem has been fixed in version 1.6.12dfsg-2. We recommend that you upgrade your samba packages.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2010-3315
DSA-2118-1
Platform(s):Debian GNU/Linux 5.0
Product(s):subversion
Definition Synopsis
  • Debian GNU/Linux 5.0 is installed
  • AND Architecture section
  • Architecture independet section
  • Installed architecture is all
  • AND Packages section
  • subversion-tools DPKG is earlier than 1.5.1dfsg1-5
  • OR libsvn-doc DPKG is earlier than 1.5.1dfsg1-5
  • OR libsvn-ruby DPKG is earlier than 1.5.1dfsg1-5
  • OR libsvn-dev DPKG is earlier than 1.5.1dfsg1-5
  • OR libapache2-svn DPKG is earlier than 1.5.1dfsg1-5
  • OR libsvn-ruby1.8 DPKG is earlier than 1.5.1dfsg1-5
  • OR python-subversion DPKG is earlier than 1.5.1dfsg1-5
  • OR libsvn1 DPKG is earlier than 1.5.1dfsg1-5
  • OR subversion DPKG is earlier than 1.5.1dfsg1-5
  • OR libsvn-perl DPKG is earlier than 1.5.1dfsg1-5
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is armel
  • OR Installed architecture is ia64
  • AND libsvn-java DPKG is earlier than 1.5.1dfsg1-5
  • BACK