![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.50330 |
Category: | Fedora Local Security Checks |
Title: | Fedora Core 1 FEDORA-2004-165 (subversion) |
Summary: | NOSUMMARY |
Description: | Description: The remote host is missing an update to subversion announced via advisory FEDORA-2004-165. Subversion is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes. Subversion only stores the differences between versions, instead of every complete file. Subversion is intended to be a compelling replacement for CVS. Update Information: A heap overflow vulnerability was discovered in the svn:// protocol handling library, libsvn_ra_svn. If using the svnserve daemon, an unauthenticated client may be able execute arbitrary code as the user the daemon runs as. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0413. This issue does not affect the mod_dav_svn module. * Wed Jun 09 2004 Joe Orton - add security fix for CVE CVE-2004-0413 (Ben Reser) This update can be downloaded from: http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ 85bb51a2273fe862a534db45c0f98cef SRPMS/subversion-0.32.1-5.src.rpm 3e65c8863d12a8290465c34c9cff8c86 i386/subversion-0.32.1-5.i386.rpm 73415d6b6966fac671d44542e356a209 i386/subversion-devel-0.32.1-5.i386.rpm e54233f3d5c996bc031cfd92c7c333ca i386/mod_dav_svn-0.32.1-5.i386.rpm 5141615f39974fde3a0564c5d37c2fdf i386/debug/subversion-debuginfo-0.32.1-5.i386.rpm dfdb41c89a5d39215a461a7407acf57d x86_64/subversion-0.32.1-5.x86_64.rpm 01d85453b31a93d7c9631af526cbc2b1 x86_64/subversion-devel-0.32.1-5.x86_64.rpm f85473c36affcce1c4e84bde330e1f36 x86_64/mod_dav_svn-0.32.1-5.x86_64.rpm a436f60e985c086cda8c76cb59329e57 x86_64/debug/subversion-debuginfo-0.32.1-5.x86_64.rpm This update can also be installed with the Update Agent you can launch the Update Agent with the 'up2date' command. Solution: Apply the appropriate updates. http://www.fedoranews.org/updates/FEDORA-2004-165.shtml Risk factor : Critical CVSS Score: 10.0 |
Cross-Ref: |
BugTraq ID: 10519 Common Vulnerability Exposure (CVE) ID: CVE-2004-0413 http://www.securityfocus.com/bid/10519 Bugtraq: 20041012 [FMADV] Subversion <= 1.04 Heap Overflow (Google Search) http://www.securityfocus.com/archive/1/365836 http://www.securityfocus.com/advisories/6847 https://bugzilla.fedora.us/show_bug.cgi?id=1748 http://www.gentoo.org/security/en/glsa/glsa-200406-07.xml SuSE Security Announcement: SuSE-SA:2004:018 (Google Search) http://www.novell.com/linux/security/advisories/2004_18_subversion.html XForce ISS Database: subversion-svn-bo(16396) https://exchange.xforce.ibmcloud.com/vulnerabilities/16396 |
Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |