Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.703231
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 3231-1 (subversion - security update)
Summary:Several vulnerabilities were discovered;in Subversion, a version control system. The Common Vulnerabilities and Exposures;project identifies the following problems:;;CVE-2015-0248;Subversion mod_dav_svn and svnserve were vulnerable to a remotely;triggerable assertion DoS vulnerability for certain requests with;dynamically evaluated revision numbers.;;CVE-2015-0251;Subversion HTTP servers allow spoofing svn:author property values;for new revisions via specially crafted v1 HTTP protocol request;sequences.
Description:Summary:
Several vulnerabilities were discovered
in Subversion, a version control system. The Common Vulnerabilities and Exposures
project identifies the following problems:

CVE-2015-0248
Subversion mod_dav_svn and svnserve were vulnerable to a remotely
triggerable assertion DoS vulnerability for certain requests with
dynamically evaluated revision numbers.

CVE-2015-0251
Subversion HTTP servers allow spoofing svn:author property values
for new revisions via specially crafted v1 HTTP protocol request
sequences.

Affected Software/OS:
subversion on Debian Linux

Solution:
For the stable distribution (wheezy),
these problems have been fixed in version 1.6.17dfsg-4+deb7u9.

For the upcoming stable distribution (jessie), these problems have been
fixed in version 1.8.10-6.

For the unstable distribution (sid), these problems have been fixed in
version 1.8.10-6.

We recommend that you upgrade your subversion packages.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2015-0248
http://lists.apple.com/archives/security-announce/2015/Sep/msg00002.html
BugTraq ID: 74260
http://www.securityfocus.com/bid/74260
Debian Security Information: DSA-3231 (Google Search)
http://www.debian.org/security/2015/dsa-3231
https://security.gentoo.org/glsa/201610-05
http://www.mandriva.com/security/advisories?name=MDVSA-2015:192
RedHat Security Advisories: RHSA-2015:1633
http://rhn.redhat.com/errata/RHSA-2015-1633.html
RedHat Security Advisories: RHSA-2015:1742
http://rhn.redhat.com/errata/RHSA-2015-1742.html
http://www.securitytracker.com/id/1033214
SuSE Security Announcement: openSUSE-SU-2015:0672 (Google Search)
http://lists.opensuse.org/opensuse-updates/2015-04/msg00008.html
http://www.ubuntu.com/usn/USN-2721-1
Common Vulnerability Exposure (CVE) ID: CVE-2015-0251
BugTraq ID: 74259
http://www.securityfocus.com/bid/74259
http://seclists.org/fulldisclosure/2015/Jun/32
CopyrightCopyright (c) 2015 Greenbone Networks GmbH http://greenbone.net

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2022 E-Soft Inc. All rights reserved.