Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Fedora 22: Security Advisory - Subversion Access Control Flaws

fedora
Calendar Grey February 29, 2016
Dist Fedora Esm H88
Keep informed about the Fedora 22 subversion patch that resolves critical access control vulnerabilities related to Apache 2.4.
This update includes the latest stable release of _Apache Subversion 1.8_, version **1.8.15**

Summary

Subversion is a concurrent version control system which enables one

or more users to collaborate in developing and maintaining a

hierarchy of files and directories while keeping a history of all

changes. Subversion only stores the differences between versions,

instead of every complete file. Subversion is intended to be a

compelling replacement for CVS.

Update Information:

This update includes the latest stable release of _Apache Subversion 1.8_, version **1.8.15**. This update fixes two security issues: * **CVE-2015-3184**: Subversion's mod_authz_svn does not properly restrict anonymous access in some mixed anonymous/authenticated environments when using Apache httpd 2.4. https://subversion.apache.org/security/CVE-2015-3184-advisory.txt * **CVE-2015-3187**: Subversion servers, both httpd and svnserve, will reveal some paths that should be hidden by path-based authz. https://subversion.apache.org/security/CVE-2015-3187-advisory.txt ### User- visible changes: #### Client-side bugfixes: * gpg-agent: fix crash with non- canonical $HOME * document svn:autoprops * cp: fix 'svn cp ^/A/D/H@1 ^/A' to properly create A * resolve: improve conflict prompts for binary files * ls: improve performance of '-v' on tag directories * improved Sqlite 3.8.9 query performance regression on externals * fixed [issue 4580](): 'svn -v st' on file externals reports ...

Change Log

References


[ 1 ] Bug #1289959 - CVE-2015-5343 subversion: (mod_dav_svn) integer overflow when parsing skel-encoded request bodies https://bugzilla.redhat.com/show_bug.cgi?id=1289959 [ 2 ] Bug #1289958 - CVE-2015-5259 subversion: integer overflow in the svn:// protocol parser https://bugzilla.redhat.com/show_bug.cgi?id=1289958 [ 3 ] Bug #1247249 - CVE-2015-3184 subversion: Mixed anonymous/authenticated path-based authz with httpd 2.4 https://bugzilla.redhat.com/show_bug.cgi?id=1247249

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update subversion' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
important
Lowest
Low
Medium
High
Critical

Name: subversion
Product: Fedora 22
Version: 1.8.15
Release: 1.fc22
Summary: A Modern Concurrent Version Control System

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here