Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian 8: DSA-3425-1 Moderate: Apache Integer Underflow Risk

debian
Calendar Grey December 16, 2015
Debian Logo
Revise subversion to address integer overflow vulnerabilities that could allow remote code execution or service disruption on Debian systems; prompt action needed for security strengthening
Ivan Zhakov discovered an integer overflow in mod_dav_svn, which allows an attacker with write access to the server to execute arbitrary code or cause a denial of service

Summary

Ivan Zhakov discovered an integer overflow in mod_dav_svn, which allows
an attacker with write access to the server to execute arbitrary code or
cause a denial of service.

The oldstable distribution (wheezy) is not affected.

For the stable distribution (jessie), this problem has been fixed in
version 1.8.10-6+deb8u2.

For the unstable distribution (sid), this problem has been fixed in
version 1.9.3-1.

We recommend that you upgrade your subversion packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Package: subversion
CVE ID: CVE-2015-5343

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here