Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.130058
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2015-0326)
Resumen:The remote host is missing an update for the 'subversion' package(s) announced via the MGASA-2015-0326 advisory.
Descripción:Summary:
The remote host is missing an update for the 'subversion' package(s) announced via the MGASA-2015-0326 advisory.

Vulnerability Insight:
Subversion's mod_authz_svn does not properly restrict anonymous access in some
mixed anonymous/authenticated environments when using Apache httpd 2.4. The
result is that anonymous access may be possible to files for which only
authenticated access should be possible (CVE-2015-3184).

Subversion servers, both httpd and svnserve, will reveal some paths that
should be hidden by path-based authz. When a node is copied from an
unreadable location to a readable location the unreadable path may be
revealed. This vulnerability only reveals the path, it does not reveal the
contents of the path (CVE-2015-3187).

This update also re-enables the java subpackage for the Mageia 5 subversion
package (mga#16075).

Affected Software/OS:
'subversion' package(s) on Mageia 4, Mageia 5.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2015-3184
http://lists.apple.com/archives/security-announce/2016/Mar/msg00003.html
BugTraq ID: 76274
http://www.securityfocus.com/bid/76274
Debian Security Information: DSA-3331 (Google Search)
http://www.debian.org/security/2015/dsa-3331
https://security.gentoo.org/glsa/201610-05
RedHat Security Advisories: RHSA-2015:1742
http://rhn.redhat.com/errata/RHSA-2015-1742.html
http://www.securitytracker.com/id/1033215
SuSE Security Announcement: openSUSE-SU-2015:1401 (Google Search)
http://lists.opensuse.org/opensuse-updates/2015-08/msg00022.html
http://www.ubuntu.com/usn/USN-2721-1
Common Vulnerability Exposure (CVE) ID: CVE-2015-3187
BugTraq ID: 76273
http://www.securityfocus.com/bid/76273
RedHat Security Advisories: RHSA-2015:1633
http://rhn.redhat.com/errata/RHSA-2015-1633.html
CopyrightCopyright (C) 2015 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.