SCIENTIFIC-LINUX-ERRATA Archives

June 2011

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Troy Dawson <[log in to unmask]>
Reply To:
Troy Dawson <[log in to unmask]>
Date:
Wed, 8 Jun 2011 16:07:26 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (89 lines)
Synopsis:    Moderate: subversion security update
Issue Date:  2011-06-08
CVE Numbers: CVE-2011-1752
              CVE-2011-1783
              CVE-2011-1921


Subversion (SVN) is a concurrent version control system which enables 
one or more users to collaborate in developing and maintaining a 
hierarchy of files and directories while keeping a history of all 
changes. The mod_dav_svn module is used with the Apache HTTP Server to 
allow access to Subversion repositories via HTTP.

An infinite loop flaw was found in the way the mod_dav_svn module 
processed certain data sets. If the SVNPathAuthz directive was set to
"short_circuit", and path-based access control for files and directories
was enabled, a malicious, remote user could use this flaw to cause the
httpd process serving the request to consume an excessive amount of 
system memory. (CVE-2011-1783)

A NULL pointer dereference flaw was found in the way the mod_dav_svn 
module processed requests submitted against the URL of a baselined 
resource. A malicious, remote user could use this flaw to cause the 
httpd process serving the request to crash. (CVE-2011-1752)

An information disclosure flaw was found in the way the mod_dav_svn
module processed certain URLs when path-based access control for files 
and directories was enabled. A malicious, remote user could possibly use 
this flaw to access certain files in a repository that would otherwise 
not be accessible to them. Note: This vulnerability cannot be triggered 
if the SVNPathAuthz directive is set to "short_circuit". (CVE-2011-1921)

All Subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, you must restart the httpd daemon, if you are using
mod_dav_svn, for the update to take effect.

SL5:
   i386
      subversion-javahl-1.6.11-7.el5_6.4.i386.rpm
      subversion-perl-1.6.11-7.el5_6.4.i386.rpm
      subversion-ruby-1.6.11-7.el5_6.4.i386.rpm
      subversion-devel-1.6.11-7.el5_6.4.i386.rpm
      subversion-debuginfo-1.6.11-7.el5_6.4.i386.rpm
      subversion-1.6.11-7.el5_6.4.i386.rpm
      mod_dav_svn-1.6.11-7.el5_6.4.i386.rpm
   x86_64
      subversion-devel-1.6.11-7.el5_6.4.x86_64.rpm
      subversion-1.6.11-7.el5_6.4.x86_64.rpm
      mod_dav_svn-1.6.11-7.el5_6.4.x86_64.rpm
      subversion-1.6.11-7.el5_6.4.i386.rpm
      subversion-perl-1.6.11-7.el5_6.4.x86_64.rpm
      subversion-debuginfo-1.6.11-7.el5_6.4.i386.rpm
      subversion-javahl-1.6.11-7.el5_6.4.x86_64.rpm
      subversion-devel-1.6.11-7.el5_6.4.i386.rpm
      subversion-debuginfo-1.6.11-7.el5_6.4.x86_64.rpm
      subversion-ruby-1.6.11-7.el5_6.4.x86_64.rpm
SL6:
   i386
      subversion-1.6.11-2.el6_1.4.i686.rpm
      subversion-debuginfo-1.6.11-2.el6_1.4.i686.rpm
      subversion-devel-1.6.11-2.el6_1.4.i686.rpm
      subversion-gnome-1.6.11-2.el6_1.4.i686.rpm
      subversion-javahl-1.6.11-2.el6_1.4.i686.rpm
      mod_dav_svn-1.6.11-2.el6_1.4.i686.rpm
      subversion-ruby-1.6.11-2.el6_1.4.i686.rpm
      subversion-perl-1.6.11-2.el6_1.4.i686.rpm
      subversion-kde-1.6.11-2.el6_1.4.i686.rpm
   x86_64
      subversion-kde-1.6.11-2.el6_1.4.i686.rpm
      subversion-javahl-1.6.11-2.el6_1.4.i686.rpm
      subversion-ruby-1.6.11-2.el6_1.4.x86_64.rpm
      subversion-kde-1.6.11-2.el6_1.4.x86_64.rpm
      subversion-perl-1.6.11-2.el6_1.4.i686.rpm
      subversion-ruby-1.6.11-2.el6_1.4.i686.rpm
      subversion-perl-1.6.11-2.el6_1.4.x86_64.rpm
      subversion-javahl-1.6.11-2.el6_1.4.x86_64.rpm
      subversion-gnome-1.6.11-2.el6_1.4.x86_64.rpm
      subversion-gnome-1.6.11-2.el6_1.4.i686.rpm
      subversion-devel-1.6.11-2.el6_1.4.x86_64.rpm
      subversion-devel-1.6.11-2.el6_1.4.i686.rpm
      subversion-debuginfo-1.6.11-2.el6_1.4.x86_64.rpm
      subversion-debuginfo-1.6.11-2.el6_1.4.i686.rpm
      mod_dav_svn-1.6.11-2.el6_1.4.x86_64.rpm
      subversion-1.6.11-2.el6_1.4.x86_64.rpm
      subversion-1.6.11-2.el6_1.4.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2