PT-2015-3388 · Apache+5 · Subversion+6
Evgeny Kotkov
·
Publicado
2015-04-02
·
Atualizado
2024-06-15
·
CVE-2015-0248
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Subversion versions 1.6.0 through 1.7.19
Subversion versions 1.8.0 through 1.8.11
Description
The issue is related to resource management errors in the mod dav svn and svnserve servers of the Subversion centralized version control system. Exploitation of this issue may allow a remote attacker to cause a denial of service when processing certain combinations of parameters related to dynamically evaluated revision numbers. This can lead to an assertion failure and abort.
Recommendations
For Subversion versions 1.6.0 through 1.7.19, update to a version outside of this range to resolve the issue.
For Subversion versions 1.8.0 through 1.8.11, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider restricting access to the mod dav svn and svnserve servers until a patch is available.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Apache Subversion
Centos
Red Hat
Subversion
Suse
Ubuntu