Fedora: 2,1: subversion Buffer overflow vulnerability
Summary
Subversion is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a
hierarchy of files and directories while keeping a history of all
changes. Subversion only stores the differences between versions,
instead of every complete file. Subversion is intended to be a
compelling replacement for CVS.
Subversion is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a
hierarchy of files and directories while keeping a history of all
changes. Subversion only stores the differences between versions,
instead of every complete file. Subversion is intended to be a
compelling replacement for CVS.
Update Information:
Stefan Esser discovered an issue in the date parsing routines in
Subversion which allows a buffer overflow. An attacker could send
malicious requests to a Subversion server (either Apache-based using
mod_dav_svn, or using the svnserve daemon) and perform arbitrary
execution of code.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0397 to this issue. This update includes
packages with a patch for this issue.
* Sat May 15 2004 Joe Orton <jorton@redhat.com> 1.0.2-2.1
- add security fix for CVE CAN-2004-0397 (Ben Reser)
* Tue May 04 2004 Joe Orton <jorton@redhat.com> 1.0.2-2
- add perl MODULE_COMPAT requirement for -perl subpackage
- move perl man pages into -perl subpackage
- clean up -perl installation and dependencies (Ville Skyttä, #123045)
This update can be downloaded from:
92cc070981eae85dc2220126a7cbd9d0 SRPMS/subversion-1.0.2-2.1.src.rpm 2ff7ecbf8f8c10b6ab761c3cbc913bf2 i386/subversion-1.0.2-2.1.i386.rpm a9e16d3...
Read the Full AdvisoryChange Log
References
Fedora Update Notification FEDORA-2004-128 2004-05-19 Product : Fedora Core 2 Name : subversion Version : 1.0.2 Release : 2.1 Summary : Modern Version Control System designed to replace CVS Description : Subversion is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes. Subversion only stores the differences between versions, instead of every complete file. Subversion is intended to be a compelling replacement for CVS.