ArchLinux: 201412-17: subversion: denial of service
Summary
- CVE-2014-3580 (denial of service)
A NULL pointer dereference flaw was found in the way mod_dav_svn handled
REPORT requests. A remote, unauthenticated attacker could use a crafted
REPORT request to crash mod_dav_svn.
- CVE-2014-8108 (denial of service)
A NULL pointer dereference flaw was found in the way mod_dav_svn handled
URIs for virtual transaction names. A remote, unauthenticated attacker
could send a request for a virtual transaction name that does not exist,
causing mod_dav_svn to crash.
Resolution
Upgrade to 1.8.11-1.
# pacman -Syu "subversion>=1.8.11-1"
The problems have been fixed upstream in version 1.8.11.
References
https://subversion.apache.org/security/CVE-2014-3580-advisory.txt https://subversion.apache.org/security/CVE-2014-8108-advisory.txt https://access.redhat.com/security/cve/CVE-2014-3580 https://access.redhat.com/security/cve/CVE-2014-8108
Workaround
None.