Moderate CentOS subversion Update

Metadata

medium
5.0
mod_dav_svn-1.6.11-11.el5_9.i386.rpm, mod_dav_svn-1.6.11-11.el5_9.x86_64.rpm, mod_dav_svn-1.6.11-9.el6_4.i686.rpm, mod_dav_svn-1.6.11-9.el6_4.x86_64.rpm, subversion-1.6.11-11.el5_9.i386.rpm, subversion-1.6.11-11.el5_9.src.rpm, subversion-1.6.11-11.el5_9.x86_64.rpm, subversion-1.6.11-9.el6_4.i686.rpm, subversion-1.6.11-9.el6_4.src.rpm, subversion-1.6.11-9.el6_4.x86_64.rpm, subversion-devel-1.6.11-11.el5_9.i386.rpm, subversion-devel-1.6.11-11.el5_9.x86_64.rpm, subversion-devel-1.6.11-9.el6_4.i686.rpm, subversion-devel-1.6.11-9.el6_4.x86_64.rpm, subversion-gnome-1.6.11-9.el6_4.i686.rpm, subversion-gnome-1.6.11-9.el6_4.x86_64.rpm, subversion-javahl-1.6.11-11.el5_9.i386.rpm, subversion-javahl-1.6.11-11.el5_9.x86_64.rpm, subversion-javahl-1.6.11-9.el6_4.i686.rpm, subversion-javahl-1.6.11-9.el6_4.x86_64.rpm, subversion-kde-1.6.11-9.el6_4.i686.rpm, subversion-kde-1.6.11-9.el6_4.x86_64.rpm, subversion-perl-1.6.11-11.el5_9.i386.rpm, subversion-perl-1.6.11-11.el5_9.x86_64.rpm, subversion-perl-1.6.11-9.el6_4.i686.rpm, subversion-perl-1.6.11-9.el6_4.x86_64.rpm, subversion-ruby-1.6.11-11.el5_9.i386.rpm, subversion-ruby-1.6.11-11.el5_9.x86_64.rpm, subversion-ruby-1.6.11-9.el6_4.i686.rpm, subversion-ruby-1.6.11-9.el6_4.x86_64.rpm, subversion-svn2cl-1.6.11-9.el6_4.noarch.rpm
CVE-2013-1845, CVE-2013-1846, CVE-2013-1847, CVE-2013-1849
rhn.redhat.com, lists.centos.org, lists.centos.org
2013-04-11
2017-07-27 19:05
ALAS-2013-180
CVE-2013-1849 subversion
CVE-2013-1845 subversion
CVE-2013-1846 subversion
CVE-2013-1847 subversion
CVE-2013-1849
CVE-2013-1846
CVE-2013-1847
CVE-2013-1845
2017-04-01 19:07
2017-01-05 20:11

Description


Updated subversion packages that fix multiple security issues are now
available for Red Hat Enterprise Linux 5 and 6.

The Red Hat Security Response Team has rated this update as having moderate
security impact. Common Vulnerability Scoring System (CVSS) base scores,
which give detailed severity ratings, are available for each vulnerability
from the CVE links in the References section.

Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access to
Subversion repositories via HTTP.

A NULL pointer dereference flaw was found in the way the mod_dav_svn module
handled PROPFIND requests on activity URLs. A remote attacker could use
this flaw to cause the httpd process serving the request to crash.
(CVE-2013-1849)

A flaw was found in the way the mod_dav_svn module handled large numbers
of properties (such as those set with the "svn propset" command). A
malicious, remote user could use this flaw to cause the httpd process
serving the request to consume an excessive amount of system memory.
(CVE-2013-1845)

Two NULL pointer dereference flaws were found in the way the mod_dav_svn
module handled LOCK requests on certain types of URLs. A malicious, remote
user could use these flaws to cause the httpd process serving the request
to crash. (CVE-2013-1846, CVE-2013-1847)

Note: The CVE-2013-1849, CVE-2013-1846, and CVE-2013-1847 issues only
caused a temporary denial of service, as the Apache HTTP Server started a
new process to replace the crashed child process. When using prefork MPM,
the crash only affected the attacker. When using worker (threaded) MPM, the
connections of other users may have been interrupted.

Red Hat would like to thank the Apache Subversion project for reporting
these issues. Upstream acknowledges Alexander Klink as the original
reporter of CVE-2013-1845; Ben Reser as the original reporter of
CVE-2013-1846; and Philip Martin and Ben Reser as the original reporters of
CVE-2013-1847.

All subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, you must restart the httpd daemon, if you are using
mod_dav_svn, for the update to take effect.
Please see https://www.redhat.com/footer/terms-of-use.html

Am I vulnerable?

The constraints below list the versions that this vulnerability is patched in, and versions that are unaffected. If a patch is ready but unrealeased, then it is pending.

Or, you can just let us figure it out for you! Appcanary continously monitor your installed packages, and tell you if any of them are vulnerable.

Sign up for monitoring

Affected package information

Release Package Patched in
5 mod_dav_svn mod_dav_svn-1.6.11-11.el5_9.i386.rpm
mod_dav_svn mod_dav_svn-1.6.11-11.el5_9.x86_64.rpm
subversion subversion-1.6.11-11.el5_9.i386.rpm
subversion subversion-1.6.11-11.el5_9.src.rpm
subversion subversion-1.6.11-11.el5_9.x86_64.rpm
subversion-devel subversion-devel-1.6.11-11.el5_9.i386.rpm
subversion-devel subversion-devel-1.6.11-11.el5_9.x86_64.rpm
subversion-javahl subversion-javahl-1.6.11-11.el5_9.i386.rpm
subversion-javahl subversion-javahl-1.6.11-11.el5_9.x86_64.rpm
subversion-perl subversion-perl-1.6.11-11.el5_9.i386.rpm
subversion-perl subversion-perl-1.6.11-11.el5_9.x86_64.rpm
subversion-ruby subversion-ruby-1.6.11-11.el5_9.i386.rpm
subversion-ruby subversion-ruby-1.6.11-11.el5_9.x86_64.rpm
6 mod_dav_svn mod_dav_svn-1.6.11-9.el6_4.i686.rpm
mod_dav_svn mod_dav_svn-1.6.11-9.el6_4.x86_64.rpm
subversion subversion-1.6.11-9.el6_4.i686.rpm
subversion subversion-1.6.11-9.el6_4.src.rpm
subversion subversion-1.6.11-9.el6_4.x86_64.rpm
subversion-devel subversion-devel-1.6.11-9.el6_4.i686.rpm
subversion-devel subversion-devel-1.6.11-9.el6_4.x86_64.rpm
subversion-gnome subversion-gnome-1.6.11-9.el6_4.i686.rpm
subversion-gnome subversion-gnome-1.6.11-9.el6_4.x86_64.rpm
subversion-javahl subversion-javahl-1.6.11-9.el6_4.i686.rpm
subversion-javahl subversion-javahl-1.6.11-9.el6_4.x86_64.rpm
subversion-kde subversion-kde-1.6.11-9.el6_4.i686.rpm
subversion-kde subversion-kde-1.6.11-9.el6_4.x86_64.rpm
subversion-perl subversion-perl-1.6.11-9.el6_4.i686.rpm
subversion-perl subversion-perl-1.6.11-9.el6_4.x86_64.rpm
subversion-ruby subversion-ruby-1.6.11-9.el6_4.i686.rpm
subversion-ruby subversion-ruby-1.6.11-9.el6_4.x86_64.rpm
subversion-svn2cl subversion-svn2cl-1.6.11-9.el6_4.noarch.rpm