Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Ubuntu 14.04 LTS: USN-2721-1 Moderate: Subversion Denial Of Service

ubuntu
Calendar Grey August 20, 2015
Scroller Ubuntu
The recent Ubuntu Security Notice USN-2721-1 addresses various vulnerabilities found in Subversion, affecting multiple long-term support versions of Ubuntu.
Several security issues were fixed in Subversion.

Summary

Several security issues were fixed in Subversion.

Software Description:

- subversion: Advanced version control system

Details:

It was discovered that the Subversion mod_dav_svn module incorrectly

handled REPORT requests for a resource that does not exist. A remote

attacker could use this issue to cause the server to crash, resulting in a

denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu

14.04 LTS. (CVE-2014-3580)

It was discovered that the Subversion mod_dav_svn module incorrectly

handled requests requiring a lookup for a virtual transaction name that

does not exist. A remote attacker could use this issue to cause the server

to crash, resulting in a denial of service. This issue only affected Ubuntu

14.04 LTS. (CVE-2014-8108)

Evgeny Kotkov discovered that the Subversion mod_dav_svn module incorrectly

handled large numbers of REPORT requests. A remote attacker could use this

issue to cause the server to crash, resulting in a denial of...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.04:
  libapache2-svn                  1.8.10-5ubuntu1.1
  libsvn1                         1.8.10-5ubuntu1.1
  subversion                      1.8.10-5ubuntu1.1

Ubuntu 14.04 LTS:
  libapache2-svn                  1.8.8-1ubuntu3.2
  libsvn1                         1.8.8-1ubuntu3.2
  subversion                      1.8.8-1ubuntu3.2

Ubuntu 12.04 LTS:
  libapache2-svn                  1.6.17dfsg-3ubuntu3.5
  libsvn1                         1.6.17dfsg-3ubuntu3.5
  subversion                      1.6.17dfsg-3ubuntu3.5

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2721-1

CVE-2014-3580, CVE-2014-8108, CVE-2015-0202, CVE-2015-0248,

CVE-2015-0251, CVE-2015-3184, CVE-2015-3187

Severity
important
Lowest
Low
Medium
High
Critical

August 20, 2015

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.