Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.120506
Kategorie:Amazon Linux Local Security Checks
Titel:Amazon Linux: Security Advisory (ALAS-2015-587)
Zusammenfassung:The remote host is missing an update for the 'subversion, mod_dav_svn' package(s) announced via the ALAS-2015-587 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'subversion, mod_dav_svn' package(s) announced via the ALAS-2015-587 advisory.

Vulnerability Insight:
The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large number of REPORT requests, which trigger the traversal of FSFS repository nodes. (CVE-2015-0202)

An assertion failure flaw was found in the way the SVN server processed certain requests with dynamically evaluated revision numbers. A remote attacker could use this flaw to cause the SVN server (both svnserve and httpd with the mod_dav_svn module) to crash. (CVE-2015-0248)

It was found that the mod_dav_svn module did not properly validate the svn:author property of certain requests. An attacker able to create new revisions could use this flaw to spoof the svn:author property. (CVE-2015-0251)

Affected Software/OS:
'subversion, mod_dav_svn' package(s) on Amazon Linux.

Solution:
Please install the updated package(s).

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2015-0202
BugTraq ID: 76446
http://www.securityfocus.com/bid/76446
https://security.gentoo.org/glsa/201610-05
http://www.mandriva.com/security/advisories?name=MDVSA-2015:192
http://www.securitytracker.com/id/1032100
SuSE Security Announcement: openSUSE-SU-2015:0672 (Google Search)
http://lists.opensuse.org/opensuse-updates/2015-04/msg00008.html
http://www.ubuntu.com/usn/USN-2721-1
Common Vulnerability Exposure (CVE) ID: CVE-2015-0248
http://lists.apple.com/archives/security-announce/2015/Sep/msg00002.html
BugTraq ID: 74260
http://www.securityfocus.com/bid/74260
Debian Security Information: DSA-3231 (Google Search)
http://www.debian.org/security/2015/dsa-3231
RedHat Security Advisories: RHSA-2015:1633
http://rhn.redhat.com/errata/RHSA-2015-1633.html
RedHat Security Advisories: RHSA-2015:1742
http://rhn.redhat.com/errata/RHSA-2015-1742.html
http://www.securitytracker.com/id/1033214
Common Vulnerability Exposure (CVE) ID: CVE-2015-0251
BugTraq ID: 74259
http://www.securityfocus.com/bid/74259
http://seclists.org/fulldisclosure/2015/Jun/32
CopyrightCopyright (C) 2015 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.