what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Mandriva Linux Security Advisory 2013-152

Mandriva Linux Security Advisory 2013-152
Posted Apr 28, 2013
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2013-152 - Subversion's mod_dav_svn Apache HTTPD server module will use excessive amounts of memory when a large number of properties are set or deleted on a node. This can lead to a DoS. There are no known instances of this problem being observed in the wild. Subversion's mod_dav_svn Apache HTTPD server module will crash when a LOCK request is made against activity URLs. This can lead to a DoS. There are no known instances of this problem being observed in the wild. Subversion's mod_dav_svn Apache HTTPD server module will crash in some circumstances when a LOCK request is made against a non-existent URL. This can lead to a DoS. There are no known instances of this problem being observed in the wild. Subversion's mod_dav_svn Apache HTTPD server module will crash when a PROPFIND request is made against activity URLs. This can lead to a DoS. There are no known instances of this problem being observed in the wild, but the details of how to exploit it have been disclosed on the full disclosure mailing list. The updated packages have been upgraded to the 1.6.21 version which is not affected by these issues.

tags | advisory
systems | linux, mandriva
advisories | CVE-2013-1845, CVE-2013-1846, CVE-2013-1847, CVE-2013-1849
SHA-256 | 930a2bdd3266063666866847cb602e153af6288c4df4eadd20f0f8eba4ad4b09

Mandriva Linux Security Advisory 2013-152

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2013:152
https://www.mandriva.com/en/support/security/
_______________________________________________________________________

Package : subversion
Date : April 26, 2013
Affected: Enterprise Server 5.0
_______________________________________________________________________

Problem Description:

Multiple vulnerabilities has been found and corrected in subversion:

Subversion's mod_dav_svn Apache HTTPD server module will use excessive
amounts of memory when a large number of properties are set or deleted
on a node. This can lead to a DoS. There are no known instances of
this problem being observed in the wild (CVE-2013-1845).

Subversion's mod_dav_svn Apache HTTPD server module will crash when
a LOCK request is made against activity URLs. This can lead to a
DoS. There are no known instances of this problem being observed in
the wild (CVE-2013-1846).

Subversion's mod_dav_svn Apache HTTPD server module will crash in
some circumstances when a LOCK request is made against a non-existent
URL. This can lead to a DoS. There are no known instances of this
problem being observed in the wild (CVE-2013-1847).

Subversion's mod_dav_svn Apache HTTPD server module will crash when
a PROPFIND request is made against activity URLs. This can lead to a
DoS. There are no known instances of this problem being observed in
the wild, but the details of how to exploit it have been disclosed
on the full disclosure mailing list (CVE-2013-1849).

The updated packages have been upgraded to the 1.6.21 version which
is not affected by these issues.
_______________________________________________________________________

References:

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1845
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1846
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1847
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1849
https://subversion.apache.org/security/CVE-2013-1845-advisory.txt
https://subversion.apache.org/security/CVE-2013-1846-advisory.txt
https://subversion.apache.org/security/CVE-2013-1847-advisory.txt
https://subversion.apache.org/security/CVE-2013-1849-advisory.txt
_______________________________________________________________________

Updated Packages:

Mandriva Enterprise Server 5:
01ca2eecdec867e6482b72d56d59f297 mes5/i586/apache-mod_dav_svn-1.6.21-0.1mdvmes5.2.i586.rpm
f4858616ec625b76632955a3c4f0201b mes5/i586/apache-mod_dontdothat-1.6.21-0.1mdvmes5.2.i586.rpm
81375e280a20a0cae8b95f15779b50c9 mes5/i586/libsvn0-1.6.21-0.1mdvmes5.2.i586.rpm
0194663a7aa650742c21b19535da7db9 mes5/i586/libsvnjavahl1-1.6.21-0.1mdvmes5.2.i586.rpm
bbd8cb1cb5016ff64d8c26bc35af98e5 mes5/i586/perl-SVN-1.6.21-0.1mdvmes5.2.i586.rpm
9068de03c3d850b5bb050bc5a582d885 mes5/i586/python-svn-1.6.21-0.1mdvmes5.2.i586.rpm
bc76933bb1f1349d37b889d8d3a5d1d5 mes5/i586/ruby-svn-1.6.21-0.1mdvmes5.2.i586.rpm
a3674f9bd14e13cfb684821971112ee6 mes5/i586/subversion-1.6.21-0.1mdvmes5.2.i586.rpm
bfab26ea3f2d5ecd55e5350fe7a6e6c0 mes5/i586/subversion-devel-1.6.21-0.1mdvmes5.2.i586.rpm
20c206e8318bbc09cb289ced9de0812e mes5/i586/subversion-doc-1.6.21-0.1mdvmes5.2.i586.rpm
255c1ba61e91a945257640270cc1de73 mes5/i586/subversion-server-1.6.21-0.1mdvmes5.2.i586.rpm
9c6743ee825f3f9d71e98c6007c17de5 mes5/i586/subversion-tools-1.6.21-0.1mdvmes5.2.i586.rpm
4f88ebb8caf198a907a3b861e1bf8683 mes5/i586/svn-javahl-1.6.21-0.1mdvmes5.2.i586.rpm
6d6973f61a318530b78046f115ea0d64 mes5/SRPMS/subversion-1.6.21-0.1mdvmes5.2.src.rpm

Mandriva Enterprise Server 5/X86_64:
19813fb2e9b28a368f8ba8c1637cdefb mes5/x86_64/apache-mod_dav_svn-1.6.21-0.1mdvmes5.2.x86_64.rpm
477c2bc44a5a59365d0b199b2aec30e0 mes5/x86_64/apache-mod_dontdothat-1.6.21-0.1mdvmes5.2.x86_64.rpm
ff0fda86a6ca2d989b26d06a239e104e mes5/x86_64/lib64svn0-1.6.21-0.1mdvmes5.2.x86_64.rpm
b0f45a52e0cb62518fd2eba747f7296f mes5/x86_64/lib64svnjavahl1-1.6.21-0.1mdvmes5.2.x86_64.rpm
73475d40bce1b1bed2d09ed384a7dadd mes5/x86_64/perl-SVN-1.6.21-0.1mdvmes5.2.x86_64.rpm
26bc46bfb6f2eb419a60cd8eb24695fb mes5/x86_64/python-svn-1.6.21-0.1mdvmes5.2.x86_64.rpm
651048764744b4813bb7028ded94b670 mes5/x86_64/ruby-svn-1.6.21-0.1mdvmes5.2.x86_64.rpm
41c4d3fc4ebb30df80cafb372d51eff1 mes5/x86_64/subversion-1.6.21-0.1mdvmes5.2.x86_64.rpm
7d33856690ade09f91de86a70702a0ba mes5/x86_64/subversion-devel-1.6.21-0.1mdvmes5.2.x86_64.rpm
b1cfdbf4d1fa023640e59b709a114ad0 mes5/x86_64/subversion-doc-1.6.21-0.1mdvmes5.2.x86_64.rpm
4e35ad407cffa9cfee09dc02675d99f9 mes5/x86_64/subversion-server-1.6.21-0.1mdvmes5.2.x86_64.rpm
7723aa67d59f81fa693ba6a2e34b507a mes5/x86_64/subversion-tools-1.6.21-0.1mdvmes5.2.x86_64.rpm
85e266caa0ae80bbc8416fd8038f32b2 mes5/x86_64/svn-javahl-1.6.21-0.1mdvmes5.2.x86_64.rpm
6d6973f61a318530b78046f115ea0d64 mes5/SRPMS/subversion-1.6.21-0.1mdvmes5.2.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

https://www.mandriva.com/en/support/security/advisories/

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iD8DBQFRejMQmqjQ0CJFipgRAklHAJ4xHOnB++FaGe2Gi/ek8aX081FePgCgmOuF
qJeXPdHQ7VRFRUtSqz0y5Sg=
=MHqP
-----END PGP SIGNATURE-----


Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    69 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close