Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Fedora: CAN-2004-0397 Critical: Subversion Buffer Overflow Threat

fedora
Calendar Grey May 19, 2004
Scroller Fedora
A critical security notice for Fedora warns users about a buffer overflow flaw present in Subversion, which poses a risk of unauthorized code execution.
An attacker could send malicious requests to a Subversion server and perform arbitrary execution of code.

Summary

Subversion is a concurrent version control system which enables one

or more users to collaborate in developing and maintaining a

hierarchy of files and directories while keeping a history of all

changes. Subversion only stores the differences between versions,

instead of every complete file. Subversion is intended to be a

compelling replacement for CVS.

Subversion is a concurrent version control system which enables one

or more users to collaborate in developing and maintaining a

hierarchy of files and directories while keeping a history of all

changes. Subversion only stores the differences between versions,

instead of every complete file. Subversion is intended to be a

compelling replacement for CVS.

Update Information:

Stefan Esser discovered an issue in the date parsing routines in Subversion which allows a buffer overflow. An attacker could send malicious requests to a Subversion server (either Apache-based using mod_dav_svn, or using the svnserve daemon) and perform arbitrary execution of code.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0397 to this issue. This update includes packages with a patch for this issue.

* Sat May 15 2004 Joe Orton <jorton@redhat.com> 1.0.2-2.1

- add security fix for CVE CAN-2004-0397 (Ben Reser)

* Tue May 04 2004 Joe Orton <jorton@redhat.com> 1.0.2-2

- add perl MODULE_COMPAT requirement for -perl subpackage - move perl man pages into -perl subpackage - clean up -perl installation and dependencies (Ville Skyttä, #123045)


This update can be downloaded from:


92cc070981eae85dc2220126a7cbd9d0 SRPMS/subversion-1.0.2-2.1.src.rpm 2ff7ecbf8f8c10b6ab761c3cbc913bf2 i386/subversion-1.0.2-2.1.i386.rpm a9e16d3...

Read the Full Advisory

Change Log

References

Fedora Update Notification FEDORA-2004-128 2004-05-19
Product : Fedora Core 2 Name : subversion Version : 1.0.2 Release : 2.1 Summary : Modern Version Control System designed to replace CVS Description : Subversion is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes. Subversion only stores the differences between versions, instead of every complete file. Subversion is intended to be a compelling replacement for CVS.

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora Core 2
Name: subversion
Version: 1.0.2
Release: 2.1
Summary: Modern Version Control System designed to replace CVS
Product: Fedora Core 1
Name: subversion
Version: 0.32.1
Release: 2
Summary: A Concurrent Versioning system similar to, but better than, CVS.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.