Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Ubuntu 11.04 USN-1144-1 Moderate: Subversion Denial Of Service Threats

ubuntu
Calendar Grey June 6, 2011
Scroller Ubuntu
Ubuntu Security Notice USN-1145-2 highlights vulnerabilities in Git that may result in unauthorized access to confidential information on Nginx.
An attacker could send crafted input to the Subversion mod_dav_svn module for Apache and cause it to crash or gain access to restricted files.

Summary

An attacker could send crafted input to the Subversion mod_dav_svn module

for Apache and cause it to crash or gain access to restricted files.

Software Description:

- subversion: Advanced version control system

Details:

Joe Schaefer discovered that the Subversion mod_dav_svn module for Apache

did not properly handle certain baselined WebDAV resource requests. A

remote attacker could use this flaw to cause the service to crash, leading

to a denial of service. (CVE-2011-1752)

Ivan Zhakov discovered that the Subversion mod_dav_svn module for Apache

did not properly handle certain requests. A remote attacker could use this

flaw to cause the service to consume all available resources, leading to a

denial of service. (CVE-2011-1783)

Kamesh Jayachandran discovered that the Subversion mod_dav_svn module for

Apache did not properly handle access control in certain situations. A

remote user could use this flaw to gain access to files that would

otherwise be unreada...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
  libapache2-svn                  1.6.12dfsg-4ubuntu2.1

Ubuntu 10.10:
  libapache2-svn                  1.6.12dfsg-1ubuntu1.3

Ubuntu 10.04 LTS:
  libapache2-svn                  1.6.6dfsg-2ubuntu1.3

After a standard system update you need to restart any applications that
use Subversion, such as Apache when using mod_dav_svn, to make all the
necessary changes.

References

CVE-2011-1752, CVE-2011-1783, CVE-2011-1921

June 06, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.