Oval Definition:oval:org.mitre.oval:def:27062
Revision Date:2014-12-08Version:9
Title:RHSA-2014:0255 -- subversion security update (Moderate)
Description:Subversion (SVN) is a concurrent version control system which enables oneor more users to collaborate in developing and maintaining a hierarchy offiles and directories while keeping a history of all changes. Themod_dav_svn module is used with the Apache HTTP Server to allow access toSubversion repositories via HTTP.A flaw was found in the way the mod_dav_svn module handled OPTIONSrequests. A remote attacker with read access to an SVN repository servedvia HTTP could use this flaw to cause the httpd process that handled such arequest to crash. (CVE-2014-0032)A flaw was found in the way Subversion handled file names with newlinecharacters when the FSFS repository format was used. An attacker withcommit access to an SVN repository could corrupt a revision by committing aspecially crafted file. (CVE-2013-1968)A flaw was found in the way the svnserve tool of Subversion handled remoteclient network connections. An attacker with read access to an SVNrepository served via svnserve could use this flaw to cause the svnservedaemon to exit, leading to a denial of service. (CVE-2013-2112)All subversion users should upgrade to these updated packages, whichcontain backported patches to correct these issues. After installing theupdated packages, for the update to take effect, you must restart the httpddaemon, if you are using mod_dav_svn, and the svnserve daemon, if you areserving Subversion repositories via the svn:// protocol.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2014:0255
CVE-2013-1968
CVE-2013-2112
CVE-2014-0032
RHSA-2014:0255
Platform(s):CentOS Linux 5
CentOS Linux 6
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Product(s):subversion
Definition Synopsis
  • Red Hat Enterprise Linux 5 and CentOS Linux 5 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • OR The operating system installed on the system is CentOS Linux 5.x
  • AND Packages match section
  • mod_dav_svn is earlier than 0:1.6.11-12.el5_10
  • OR subversion is earlier than 0:1.6.11-12.el5_10
  • OR subversion-devel is earlier than 0:1.6.11-12.el5_10
  • OR subversion-javahl is earlier than 0:1.6.11-12.el5_10
  • OR subversion-perl is earlier than 0:1.6.11-12.el5_10
  • OR subversion-ruby is earlier than 0:1.6.11-12.el5_10
  • Red Hat Enterprise Linux 5 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • AND subversion-debuginfo is earlier than 0:1.6.11-12.el5_10
  • Red Hat Enterprise Linux 6 and CentOS Linux 6 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • OR The operating system installed on the system is CentOS Linux 6.x
  • AND Packages match section
  • mod_dav_svn is earlier than 0:1.6.11-10.el6_5
  • OR subversion is earlier than 0:1.6.11-10.el6_5
  • OR subversion-devel is earlier than 0:1.6.11-10.el6_5
  • OR subversion-gnome is earlier than 0:1.6.11-10.el6_5
  • OR subversion-javahl is earlier than 0:1.6.11-10.el6_5
  • OR subversion-kde is earlier than 0:1.6.11-10.el6_5
  • OR subversion-perl is earlier than 0:1.6.11-10.el6_5
  • OR subversion-ruby is earlier than 0:1.6.11-10.el6_5
  • OR subversion-svn2cl is earlier than 0:1.6.11-10.el6_5
  • Red Hat Enterprise Linux 6 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • AND subversion-debuginfo is earlier than 0:1.6.11-10.el6_5
  • BACK