Lucene search

K
osvGoogleOSV:DLA-448-1
HistoryMay 01, 2016 - 12:00 a.m.

subversion - security update

2016-05-0100:00:00
Google
osv.dev
17

EPSS

0.084

Percentile

94.4%

  • CVE-2016-2167
    svnserve, the svn:// protocol server, can optionally use the Cyrus
    SASL library for authentication, integrity protection, and encryption.
    Due to a programming oversight, authentication against Cyrus SASL
    would permit the remote user to specify a realm string which is
    a prefix of the expected realm string.
  • CVE-2016-2168
    Subversion’s httpd servers are vulnerable to a remotely triggerable crash
    in the mod_authz_svn module. The crash can occur during an authorization
    check for a COPY or MOVE request with a specially crafted header value.

This allows remote attackers to cause a denial of service.

For Debian 7 Wheezy, these issues have been fixed in subversion version 1.6.17dfsg-4+deb7u11