MGASA-2014-0104
Dashboard / Vulnerabilities / MGASA-2014-0104
Summary: Updated subversion packages fix CVE-2014-0032
Details: Updated subversion packages fix security vulnerability: The mod_dav_svn module in Apache Subversion before 1.8.8, when SVNListParentPath is enabled, allows remote attackers to cause a denial of service (crash) via an OPTIONS request (CVE-2014-0032). The package has been patched to correct this issue. Additionally, the svnserve service was using the incorrect root directory for the repositories. This has also been corrected. The root directory is now defined in the /etc/sysconfig/svnserve file.
References: https://advisories.mageia.org/MGASA-2014-0104.html, https://subversion.apache.org/security/CVE-2014-0032-advisory.txt, https://mail-archives.apache.org/mod_mbox/subversion-dev/201402.mbox/%[email protected]%3E, https://bugs.mageia.org/show_bug.cgi?id=12059, https://bugs.mageia.org/show_bug.cgi?id=12768.mga3
Affected packages
Package
Name: subversion
Purl: pkg:rpm/mageia/subversion?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
