Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.131291
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2016-0161)
Resumen:The remote host is missing an update for the 'subversion' package(s) announced via the MGASA-2016-0161 advisory.
Descripción:Summary:
The remote host is missing an update for the 'subversion' package(s) announced via the MGASA-2016-0161 advisory.

Vulnerability Insight:
Updated subversion packages fix security vulnerabilities:

Daniel Shahaf and James McCoy discovered that an implementation error in the
authentication against the Cyrus SASL library would permit a remote user to
specify a realm string which is a prefix of the expected realm string and
potentially allowing a user to authenticate using the wrong realm
(CVE-2016-2167).

Ivan Zhakov of VisualSVN discovered a remotely triggerable denial of service
vulnerability in the mod_authz_svn module during COPY or MOVE authorization
check. An authenticated remote attacker could take advantage of this flaw to
cause a denial of service (Subversion server crash) via COPY or MOVE requests
with specially crafted header (CVE-2016-2168).

Affected Software/OS:
'subversion' package(s) on Mageia 5.

Solution:
Please install the updated package(s).

CVSS Score:
4.9

CVSS Vector:
AV:N/AC:M/Au:S/C:P/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2016-2167
BugTraq ID: 89417
http://www.securityfocus.com/bid/89417
http://subversion.apache.org/security/CVE-2016-2167-advisory.txt
Debian Security Information: DSA-3561 (Google Search)
http://www.debian.org/security/2016/dsa-3561
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184545.html
https://security.gentoo.org/glsa/201610-05
https://www.oracle.com/security-alerts/cpuoct2020.html
http://mail-archives.apache.org/mod_mbox/subversion-announce/201604.mbox/%3CCAP_GPNgJet+7_MAhomFVOXPgLtewcUw9w=k9zdPCkq5tvPxVMA@mail.gmail.com%3E
http://mail-archives.apache.org/mod_mbox/subversion-announce/201604.mbox/%3CCAP_GPNgfn1iKueW51EpmXzXi_URNfGNofZSgOyW1_jnSeNm5DQ@mail.gmail.com%3E
http://www.securitytracker.com/id/1035706
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.417496
SuSE Security Announcement: openSUSE-SU-2016:1263 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-05/msg00043.html
SuSE Security Announcement: openSUSE-SU-2016:1264 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-05/msg00044.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-2168
BugTraq ID: 89320
http://www.securityfocus.com/bid/89320
http://subversion.apache.org/security/CVE-2016-2168-advisory.txt
http://www.securitytracker.com/id/1035707
CopyrightCopyright (C) 2016 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.