MGASA-2015-0177
Dashboard / Vulnerabilities / MGASA-2015-0177
MGASA-2015-0177
Summary: Updated subversion packages fix security vulnerabilities
Details: Updated subversion packages fix security vulnerabilities: Subversion HTTP servers with FSFS repositories are vulnerable to a remotely triggerable excessive memory use with certain REPORT requests (CVE-2015-0202). Subversion mod_dav_svn and svnserve are vulnerable to a remotely triggerable assertion DoS vulnerability for certain requests with dynamically evaluated revision numbers (CVE-2015-0248). Subversion HTTP servers allow spoofing svn:author property values for new revisions (CVE-2015-0251).
References: https://advisories.mageia.org/MGASA-2015-0177.html, https://bugs.mageia.org/show_bug.cgi?id=15619, http://subversion.apache.org/security/CVE-2015-0202-advisory.txt, http://subversion.apache.org/security/CVE-2015-0248-advisory.txt, http://subversion.apache.org/security/CVE-2015-0251-advisory.txt
Affected packages
Package
Name: subversion
Purl: pkg:rpm/mageia/subversion?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
