MGASA-2014-0545
Dashboard / Vulnerabilities / MGASA-2014-0545
Summary: Updated subversion packages fix security vulnerabilities
Details: A NULL pointer dereference flaw was found in the way mod_dav_svn handled REPORT requests. A remote, unauthenticated attacker could use a crafted REPORT request to crash mod_dav_svn (CVE-2014-3580). A NULL pointer dereference flaw was found in the way mod_dav_svn handled URIs for virtual transaction names. A remote, unauthenticated attacker could send a request for a virtual transaction name that does not exist, causing mod_dav_svn to crash (CVE-2014-8108).
References: https://advisories.mageia.org/MGASA-2014-0545.html, https://bugs.mageia.org/show_bug.cgi?id=14826, http://subversion.apache.org/security/CVE-2014-3580-advisory.txt, http://subversion.apache.org/security/CVE-2014-8108-advisory.txt, https://bugzilla.redhat.com/show_bug.cgi?id=1174054, https://bugzilla.redhat.com/show_bug.cgi?id=1174057
Affected packages
Package
Name: subversion
Purl: pkg:rpm/mageia/subversion?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
