Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 14.04/12.04 LTS: USN-2316-1 Critical: Subversion DoS and MITM

ubuntu
Calendar Grey August 14, 2014
Scroller Ubuntu
Numerous vulnerabilities patched in Subversion impacting Ubuntu versions 12.04 and 14.04 LTS; ensure your system is protected by updating.
Several security issues were fixed in Subversion.

Summary

Several security issues were fixed in Subversion.

Software Description:

- subversion: Advanced version control system

Details:

Lieven Govaerts discovered that the Subversion mod_dav_svn module

incorrectly handled certain request methods when SVNListParentPath was

enabled. A remote attacker could use this issue to cause the server to

crash, resulting in a denial of service. This issue only affected Ubuntu

12.04 LTS. (CVE-2014-0032)

Ben Reser discovered that Subversion did not correctly validate SSL

certificates containing wildcards. A remote attacker could exploit this to

perform a man in the middle attack to view sensitive information or alter

encrypted communications. (CVE-2014-3522)

Bert Huijben discovered that Subversion did not properly handle cached

credentials. A malicious server could possibly use this issue to obtain

credentials cached for a different server. (CVE-2014-3528)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  libsvn1                         1.8.8-1ubuntu3.1
  subversion                      1.8.8-1ubuntu3.1

Ubuntu 12.04 LTS:
  libapache2-svn                  1.6.17dfsg-3ubuntu3.4
  libsvn1                         1.6.17dfsg-3ubuntu3.4
  subversion                      1.6.17dfsg-3ubuntu3.4

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2316-1

CVE-2014-0032, CVE-2014-3522, CVE-2014-3528

Severity
critical
Lowest
Low
Medium
High
Critical

August 14, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.