UBUNTU-CVE-2020-17525
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-17525
UBUNTU-CVE-2020-17525
Summary:
Details: Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7
References: https://ubuntu.com/security/CVE-2020-17525, https://ubuntu.com/security/notices/USN-5322-1, https://ubuntu.com/security/notices/USN-5445-1, https://www.cve.org/CVERecord?id=CVE-2020-17525
Affected packages
Package
Name: subversion
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
