aboutsummaryrefslogtreecommitdiffstats
path: root/english/lts/security/2015/dla-207.wml
blob: 887bf0efb05dfa9548db2027b689ba164f2e1abf (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
<define-tag description>LTS security update</define-tag>
<define-tag moreinfo>
<p>Several vulnerabilities were discovered in Subversion, a version control
system. The Common Vulnerabilities and Exposures project identifies the
following problems:</p>

<ul>

<li><a href="https://security-tracker.debian.org/tracker/CVE-2015-0248">CVE-2015-0248</a>

    <p>Subversion mod_dav_svn and svnserve were vulnerable to a remotely
    triggerable assertion DoS vulnerability for certain requests with
    dynamically evaluated revision numbers.</p></li>

<li><a href="https://security-tracker.debian.org/tracker/CVE-2015-0251">CVE-2015-0251</a>

    <p>Subversion HTTP servers allow spoofing svn:author property values for
    new revisions via specially crafted v1 HTTP protocol request
    sequences.</p></li>

<li><a href="https://security-tracker.debian.org/tracker/CVE-2013-1845">CVE-2013-1845</a>

    <p>Subversion mod_dav_svn was vulnerable to a denial of service attack
    through a remotely triggered memory exhaustion.</p></li>

<li><a href="https://security-tracker.debian.org/tracker/CVE-2013-1846">CVE-2013-1846</a> / <a href="https://security-tracker.debian.org/tracker/CVE-2013-1847">CVE-2013-1847</a> / <a href="https://security-tracker.debian.org/tracker/CVE-2013-1849">CVE-2013-1849</a> / <a href="https://security-tracker.debian.org/tracker/CVE-2014-0032">CVE-2014-0032</a>

    <p>Subversion mod_dav_svn was vulnerable to multiple remotely triggered
    crashes.</p></li>

</ul>

<p>This update has been prepared by James McCoy.</p>
</define-tag>

# do not modify the following line
#include "$(ENGLISHDIR)/lts/security/2015/dla-207.data"
# $Id$

© 2014-2024 Faster IT GmbH | imprint | privacy policy