PT-2007-1129 · Apache · Apache Subversion
Published
2007-04-10
·
Updated
2024-06-15
·
CVE-2013-4246
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Apache Subversion versions 1.8.x through 1.8.1
Description:
The issue is related to incorrect access control in the libsvn fs fs/fs fs.c component of the centralized version control system. This can be exploited by a remote authenticated user with commit access to corrupt FSFS repositories, potentially leading to a denial of service or obtaining sensitive information by editing packed revision properties. The corruption of Subversion FSFS repositories can occur when packed revision properties are edited, specifically when one or more revision properties of a packed revision are set to new, larger values, causing a "pack file" in the repository to be split and potentially leading to the deletion of the wrong pack file, resulting in data loss of revision property data.
Recommendations:
For Apache Subversion versions 1.8.x through 1.8.1, update to version 1.8.2 or later to resolve the issue.
Fix
DoS
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Subversion