Fedora: 2,1: subversion Heap overflow vulnerability
Summary
Subversion is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a
hierarchy of files and directories while keeping a history of all
changes. Subversion only stores the differences between versions,
instead of every complete file. Subversion is intended to be a
compelling replacement for CVS.
Subversion is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a
hierarchy of files and directories while keeping a history of all
changes. Subversion only stores the differences between versions,
instead of every complete file. Subversion is intended to be a
compelling replacement for CVS.
Update Information:
A heap overflow vulnerability was discovered in the svn:// protocol
handling library, libsvn_ra_svn. If using the svnserve daemon,
an unauthenticated client may be able execute arbitrary code as
the user the daemon runs as. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0413.
This issue does not affect the mod_dav_svn module.
* Mon Jun 07 2004 Joe Orton <jorton@redhat.com> 1.0.4-2
- add ra_svn security fix for CVE CAN-2004-0413 (Ben Reser)
This update can be downloaded from:
453a16f649e7b5ff502d6379253bbb05 SRPMS/subversion-1.0.4-2.src.rpm 746cc7b03fe3e4b02f7374b8a03850ad i386/subversion-1.0.4-2.i386.rpm 1dd7fd91e468d7af15e1d253c7ef1f08 i386/subversion-devel-1.0.4-2.i386.rpm 05adf7825b9d708c9eba80f359fa33d7 i386/mod_dav_svn-1.0.4-2.i386.rpm 09a54699d17c43dc7f0e585acea64455 i386/subversion-perl-1.0.4-2.i386.rpm 7c5040ab4f0cf6c5305d8edb686c0b5c i386/debug/subversion-debuginfo-1.0.4-2.i386.rpm 640cafcc4e668e1ddf643d10d743e4...
Read the Full AdvisoryChange Log
References
CORE 2: Fedora Update Notification FEDORA-2004-166 2004-06-11 Product : Fedora Core 2 Name : subversion Version : 1.0.4 Release : 2 Summary : Modern Version Control System designed to replace CVS Description : Subversion is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes. Subversion only stores the differences between versions, instead of every complete file. Subversion is intended to be a compelling replacement for CVS.