Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2013.0360
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2013-0360)
Summary:The remote host is missing an update for the 'subversion' package(s) announced via the MGASA-2013-0360 advisory.
Description:Summary:
The remote host is missing an update for the 'subversion' package(s) announced via the MGASA-2013-0360 advisory.

Vulnerability Insight:
mod_dontdothat allows you to block update REPORT requests against certain
paths in the repository. It expects the paths in the REPORT request to be
absolute URLs. Serf based clients send relative URLs instead of absolute
URLs in many cases. As a result these clients are not blocked as
configured by mod_dontdothat (CVE-2013-4505).

When SVNAutoversioning is enabled via 'SVNAutoversioning on', commits can
be made by single HTTP requests such as MKCOL and PUT. If Subversion is
built with assertions enabled any such requests that have non-canonical
URLs, such as URLs with a trailing /, may trigger an assert. An assert
will cause the Apache process to abort (CVE-2013-4558).

Affected Software/OS:
'subversion' package(s) on Mageia 3.

Solution:
Please install the updated package(s).

CVSS Score:
3.5

CVSS Vector:
AV:N/AC:M/Au:S/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-4505
http://osvdb.org/100364
http://secunia.com/advisories/55855
SuSE Security Announcement: openSUSE-SU-2013:1836 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-12/msg00029.html
SuSE Security Announcement: openSUSE-SU-2013:1860 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-12/msg00048.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-4558
100363
http://osvdb.org/100363
http://subversion.apache.org/security/CVE-2013-4558-advisory.txt
https://bugzilla.redhat.com/show_bug.cgi?id=1033431
https://github.com/apache/subversion/commit/2c77c43e4255555f3b79f761f0d141393a3856cc
https://github.com/apache/subversion/commit/647e3f8365a74831bb915f63793b63e31fae062d
openSUSE-SU-2013:1836
openSUSE-SU-2013:1860
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.