SUSE-SU-2015:0776-1
Dashboard / Vulnerabilities / SUSE-SU-2015:0776-1
SUSE-SU-2015:0776-1
Summary: Security update for subversion
Details: Apache Subversion was updated to fix three vulnerabilities. The following vulnerabilities were fixed: * Subversion HTTP servers with FSFS repositories were vulnerable to a remotely triggerable excessive memory use with certain REPORT requests. (bsc#923793 CVE-2015-0202) * Subversion mod_dav_svn and svnserve were vulnerable to a remotely triggerable assertion DoS vulnerability for certain requests with dynamically evaluated revision numbers. (bsc#923794 CVE-2015-0248) * Subversion HTTP servers allow spoofing svn:author property values for new revisions (bsc#923795 CVE-2015-0251)
References: https://www.suse.com/support/update/announcement/2015/suse-su-20150776-1/, https://bugzilla.suse.com/923793, https://bugzilla.suse.com/923794, https://bugzilla.suse.com/923795, https://www.suse.com/security/cve/CVE-2015-0202, https://www.suse.com/security/cve/CVE-2015-0248, https://www.suse.com/security/cve/CVE-2015-0251
Affected packages
Package
Name: subversion
Purl: pkg:rpm/suse/subversion&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012
Affected ranges
Type: ECOSYSTEM
Events:
