Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 10 Subversion 1.6.4-2 Critical: Heap Overflow Risk Mitigated

fedora
Calendar Grey August 10, 2009
Dist Fedora Esm H88
Subversion 1.6.4-2.fc10 patch resolves several memory corruption issues, boosting reliability and protection in Fedora. Discover more!
This update includes the latest stable release of Subversion, including several enhancements, many bug fixes, and a fix for a security issue: Matt Lewis reported multiple heap ...

Summary

Subversion is a concurrent version control system which enables one

or more users to collaborate in developing and maintaining a

hierarchy of files and directories while keeping a history of all

changes. Subversion only stores the differences between versions,

instead of every complete file. Subversion is intended to be a

compelling replacement for CVS.

Update Information:

This update includes the latest stable release of Subversion, including several enhancements, many bug fixes, and a fix for a security issue: Matt Lewis reported multiple heap overflow flaws in Subversion (servers and clients) when parsing binary deltas. Malicious users with commit access to a vulnerable server could uses these flaws to cause a heap overflow on the server running Subversion. A malicious Subversion server could use these flaws to cause a heap overflow on vulnerable clients when they attempt to checkout or update, resulting in a crash or, possibly, arbitrary code execution on the vulnerable client. (CVE-2009-2411) Version 1.6 offers many bug fixes and enhancements over 1.5, with the notable major features: - identical files share storage space in repository - file-externals support for intra-repository files - "tree" conflicts now handled more gracefully - repository root relative URL support on most commands For more information on changes in 1.6, see ...

Change Log

* Fri Aug 7 2009 Joe Orton 1.6.4-2 - update to 1.6.4 * Thu May 28 2009 Joe Orton 1.6.2-2.fc10 - update to 1.6.2 (#500933, #469524) * Fri Jan 30 2009 Joe Orton 1.5.5-4.fc10 - rebuild

References


[ 1 ] Bug #514744 - CVE-2009-2411 subversion: integer overflow https://bugzilla.redhat.com/show_bug.cgi?id=514744

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update subversion' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: subversion
Product: Fedora 10
Version: 1.6.4
Release: 2.fc10
URL: Summary : A Modern Concurrent Version Control System

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here