Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.69314
Category:Fedora Local Security Checks
Title:Fedora Core 15 FEDORA-2011-3775 (subversion)
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to subversion
announced via advisory FEDORA-2011-3775.

Update Information:

A NULL pointer dereference flaw was found in the way the mod_dav_svn module processed certain requests to lock working copy paths in a repository. A remote attacker could issue a lock request that could cause the httpd process serving the request to crash. (CVE-2011-0715)

The Fedora Project would like to thank Hyrum Wright of the Apache Subversion project for reporting this issue. Upstream acknowledges Philip Martin, WANdisco, Inc. as the original reporter.

Several bugs are also fixed in this update:

* more improvement to the 'blame -g' memory leak from 1.6.15
* avoid unnecessary globbing for performance
* don't add tree conflicts when one already exists
* fix potential crash when requesting mergeinfo
* don't attempt to resolve prop conflicts in 'merge --dry-run'

References:

[ 1 ] Bug #680755 - CVE-2011-0715 subversion (mod_dav_svn): DoS (NULL ptr deref) by a lock token sent from a not authenticated Subversion client
https://bugzilla.redhat.com/show_bug.cgi?id=680755

Solution: Apply the appropriate updates.

This update can be installed with the yum update program. Use
su -c 'yum update subversion' at the command line.
For more information, refer to Managing Software with yum,
available at http://docs.fedoraproject.org/yum/.

http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2011-3775

Risk factor : Medium

CVSS Score:
4.3

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-0715
1025161
http://securitytracker.com/id?1025161
43583
http://secunia.com/advisories/43583
43603
http://secunia.com/advisories/43603
43672
http://secunia.com/advisories/43672
43794
http://secunia.com/advisories/43794
46734
http://www.securityfocus.com/bid/46734
70964
http://www.osvdb.org/70964
ADV-2011-0567
http://www.vupen.com/english/advisories/2011/0567
ADV-2011-0568
http://www.vupen.com/english/advisories/2011/0568
ADV-2011-0624
http://www.vupen.com/english/advisories/2011/0624
ADV-2011-0660
http://www.vupen.com/english/advisories/2011/0660
ADV-2011-0684
http://www.vupen.com/english/advisories/2011/0684
ADV-2011-0776
http://www.vupen.com/english/advisories/2011/0776
ADV-2011-0885
http://www.vupen.com/english/advisories/2011/0885
APPLE-SA-2011-06-23-1
http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html
DSA-2181
http://www.debian.org/security/2011/dsa-2181
FEDORA-2011-2657
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056071.html
FEDORA-2011-2698
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056072.html
FEDORA-2011-3775
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056736.html
MDVSA-2011:067
http://www.mandriva.com/security/advisories?name=MDVSA-2011:067
RHSA-2011:0327
https://rhn.redhat.com/errata/RHSA-2011-0327.html
RHSA-2011:0328
https://rhn.redhat.com/errata/RHSA-2011-0328.html
SSA:2011-070-01
http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.479953
SUSE-SR:2011:005
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html
USN-1096-1
http://www.ubuntu.com/usn/USN-1096-1
[dev] 20110303 Subversion 1.6.16 Released
http://svn.haxx.se/dev/archive-2011-03/0122.shtml
http://subversion.apache.org/security/CVE-2011-0715-advisory.txt
http://support.apple.com/kb/HT4723
http://svn.apache.org/repos/asf/subversion/tags/1.6.16/CHANGES
http://svn.apache.org/viewvc?view=revision&revision=1071239
http://svn.apache.org/viewvc?view=revision&revision=1071307
https://bugzilla.redhat.com/show_bug.cgi?id=680755
oval:org.mitre.oval:def:18967
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18967
subversion-moddavsvn-dos(65876)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65876
CopyrightCopyright (c) 2011 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.