Executive Summary

Summary
Title subversion security and bug fix update
Informations
Name RHSA-2011:0327 First vendor Publication 2011-03-08
Vendor RedHat Last vendor Modification 2011-03-08
Severity (Vendor) Moderate Revision 01

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:N/I:N/A:P)
Cvss Base Score 4.3 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Problem Description:

Updated subversion packages that fix one security issue and one bug are now available for Red Hat Enterprise Linux 5.

The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section.

2. Relevant releases/architectures:

RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64

3. Description:

Subversion (SVN) is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes. The mod_dav_svn module is used with the Apache HTTP Server to allow access to Subversion repositories via HTTP.

A NULL pointer dereference flaw was found in the way the mod_dav_svn module processed certain requests to lock working copy paths in a repository. A remote attacker could issue a lock request that could cause the httpd process serving the request to crash. (CVE-2011-0715)

Red Hat would like to thank Hyrum Wright of the Apache Subversion project for reporting this issue. Upstream acknowledges Philip Martin, WANdisco, Inc. as the original reporter.

This update also fixes the following bug:

* A regression was found in the handling of repositories which do not have a "db/fsfs.conf" file. The "svnadmin hotcopy" command would fail when trying to produce a copy of such a repository. This command has been fixed to ignore the absence of the "fsfs.conf" file. The "svnadmin hotcopy" command will now succeed for this type of repository. (BZ#681522)

All Subversion users should upgrade to these updated packages, which contain backported patches to correct these issues. After installing the updated packages, you must restart the httpd daemon, if you are using mod_dav_svn, for the update to take effect.

4. Solution:

Before applying this update, make sure all previously-released errata relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259

5. Bugs fixed (http://bugzilla.redhat.com/):

680755 - CVE-2011-0715 subversion (mod_dav_svn): DoS (NULL ptr deref) by a lock token sent from a not authenticated Subversion client 681522 - Regression: svnadmin hotcopy throws error

Original Source

Url : https://rhn.redhat.com/errata/RHSA-2011-0327.html

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:12980
 
Oval ID: oval:org.mitre.oval:def:12980
Title: DSA-2181-1 subversion -- denial of service
Description: Philip Martin discovered that HTTP-based Subversion servers crash when processing lock requests on repositories which support unauthenticated read access.
Family: unix Class: patch
Reference(s): DSA-2181-1
CVE-2011-0715
Version: 5
Platform(s): Debian GNU/Linux 5.0
Debian GNU/Linux 6.0
Debian GNU/kFreeBSD 6.0
Product(s): subversion
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:13766
 
Oval ID: oval:org.mitre.oval:def:13766
Title: USN-1096-1 -- subversion vulnerability
Description: Philip Martin discovered that the Subversion mod_dav_svn module for Apache did not properly handle certain requests containing a lock token. A remote attacker could use this flaw to cause the service to crash, leading to a denial of service.
Family: unix Class: patch
Reference(s): USN-1096-1
CVE-2011-0715
Version: 5
Platform(s): Ubuntu 8.04
Ubuntu 10.10
Ubuntu 10.04
Ubuntu 9.10
Ubuntu 6.06
Product(s): subversion
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:18967
 
Oval ID: oval:org.mitre.oval:def:18967
Title: Apache Subversion vulnerability before 1.6.16 in VisualSVN Server (CVE-2011-0715)
Description: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.
Family: windows Class: vulnerability
Reference(s): CVE-2011-0715
Version: 5
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Product(s): VisualSVN Server
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:21285
 
Oval ID: oval:org.mitre.oval:def:21285
Title: RHSA-2011:0327: subversion security and bug fix update (Moderate)
Description: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.
Family: unix Class: patch
Reference(s): RHSA-2011:0327-01
CESA-2011:0327
CVE-2011-0715
Version: 4
Platform(s): Red Hat Enterprise Linux 5
CentOS Linux 5
Product(s): subversion
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:21566
 
Oval ID: oval:org.mitre.oval:def:21566
Title: RHSA-2011:0328: subversion security update (Moderate)
Description: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.
Family: unix Class: patch
Reference(s): RHSA-2011:0328-01
CVE-2011-0715
Version: 4
Platform(s): Red Hat Enterprise Linux 6
Product(s): subversion
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:23126
 
Oval ID: oval:org.mitre.oval:def:23126
Title: ELSA-2011:0327: subversion security and bug fix update (Moderate)
Description: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.
Family: unix Class: patch
Reference(s): ELSA-2011:0327-01
CVE-2011-0715
Version: 6
Platform(s): Oracle Linux 5
Product(s): subversion
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:23627
 
Oval ID: oval:org.mitre.oval:def:23627
Title: ELSA-2011:0328: subversion security update (Moderate)
Description: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.
Family: unix Class: patch
Reference(s): ELSA-2011:0328-01
CVE-2011-0715
Version: 6
Platform(s): Oracle Linux 6
Product(s): subversion
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:27943
 
Oval ID: oval:org.mitre.oval:def:27943
Title: DEPRECATED: ELSA-2011-0328 -- subversion security update (moderate)
Description: [1.6.11-2.3] - add security fix for CVE-2011-0715 (#681173)
Family: unix Class: patch
Reference(s): ELSA-2011-0328
CVE-2011-0715
Version: 4
Platform(s): Oracle Linux 6
Product(s): subversion
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:28163
 
Oval ID: oval:org.mitre.oval:def:28163
Title: DEPRECATED: ELSA-2011-0327 -- subversion security and bug fix update (moderate)
Description: [1.6.11-7.3] - add fix for svnadmin hotcopy (#681522) [1.6.11-7.2] - add security fix for CVE-2011-0715 (#681171)
Family: unix Class: patch
Reference(s): ELSA-2011-0327
CVE-2011-0715
Version: 4
Platform(s): Oracle Linux 5
Product(s): subversion
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 113

OpenVAS Exploits

Date Description
2012-07-30 Name : CentOS Update for mod_dav_svn CESA-2011:0327 centos5 x86_64
File : nvt/gb_CESA-2011_0327_mod_dav_svn_centos5_x86_64.nasl
2012-07-09 Name : RedHat Update for subversion RHSA-2011:0328-01
File : nvt/gb_RHSA-2011_0328-01_subversion.nasl
2011-08-19 Name : Mac OS X v10.6.8 Multiple Vulnerabilities (2011-004)
File : nvt/secpod_macosx_su11-004.nasl
2011-08-09 Name : CentOS Update for mod_dav_svn CESA-2011:0327 centos5 i386
File : nvt/gb_CESA-2011_0327_mod_dav_svn_centos5_i386.nasl
2011-04-11 Name : Mandriva Update for subversion MDVSA-2011:067 (subversion)
File : nvt/gb_mandriva_MDVSA_2011_067.nasl
2011-04-01 Name : Ubuntu Update for subversion vulnerability USN-1096-1
File : nvt/gb_ubuntu_USN_1096_1.nasl
2011-03-24 Name : Fedora Update for subversion FEDORA-2011-2657
File : nvt/gb_fedora_2011_2657_subversion_fc14.nasl
2011-03-24 Name : Fedora Update for subversion FEDORA-2011-2698
File : nvt/gb_fedora_2011_2698_subversion_fc13.nasl
2011-03-15 Name : RedHat Update for subversion RHSA-2011:0327-01
File : nvt/gb_RHSA-2011_0327-01_subversion.nasl
2011-03-09 Name : Debian Security Advisory DSA 2181-1 (subversion)
File : nvt/deb_2181_1.nasl
2011-03-09 Name : Debian Security Advisory DSA 2182-1 (logwatch)
File : nvt/deb_2182_1.nasl
2011-03-09 Name : FreeBSD Ports: subversion
File : nvt/freebsd_subversion3.nasl
0000-00-00 Name : Slackware Advisory SSA:2011-070-01 subversion
File : nvt/esoft_slk_ssa_2011_070_01.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
70964 Subversion mod_dav_svn Lock Token NULL Dereference DoS

Subversion contains a NULL pointer dereference error in the 'mod_dav_svn' module when processing lock tokens that may be exploited via a crafted HTTP request to cause a remote denial of service.

Nessus® Vulnerability Scanner

Date Description
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : suse_11_4_libsvn_auth_gnome_keyring-1-0-110309.nasl - Type : ACT_GATHER_INFO
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : suse_11_3_libsvn_auth_gnome_keyring-1-0-110607.nasl - Type : ACT_GATHER_INFO
2013-09-24 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201309-11.nasl - Type : ACT_GATHER_INFO
2013-07-12 Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2011-0328.nasl - Type : ACT_GATHER_INFO
2013-07-12 Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2011-0327.nasl - Type : ACT_GATHER_INFO
2012-08-01 Name : The remote Scientific Linux host is missing one or more security updates.
File : sl_20110308_subversion_on_SL5_x.nasl - Type : ACT_GATHER_INFO
2011-12-13 Name : The remote SuSE 10 host is missing a security-related patch.
File : suse_cvs2svn-7560.nasl - Type : ACT_GATHER_INFO
2011-06-24 Name : The remote host is missing a Mac OS X update that fixes several security issues.
File : macosx_10_6_8.nasl - Type : ACT_GATHER_INFO
2011-06-24 Name : The remote host is missing a Mac OS X update that fixes several security issues.
File : macosx_SecUpd2011-004.nasl - Type : ACT_GATHER_INFO
2011-04-15 Name : The remote CentOS host is missing one or more security updates.
File : centos_RHSA-2011-0327.nasl - Type : ACT_GATHER_INFO
2011-04-07 Name : The remote Mandriva Linux host is missing one or more security updates.
File : mandriva_MDVSA-2011-067.nasl - Type : ACT_GATHER_INFO
2011-03-30 Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-1096-1.nasl - Type : ACT_GATHER_INFO
2011-03-27 Name : The remote Fedora host is missing a security update.
File : fedora_2011-3775.nasl - Type : ACT_GATHER_INFO
2011-03-17 Name : The remote Fedora host is missing a security update.
File : fedora_2011-2698.nasl - Type : ACT_GATHER_INFO
2011-03-17 Name : The remote Fedora host is missing a security update.
File : fedora_2011-2657.nasl - Type : ACT_GATHER_INFO
2011-03-14 Name : The remote Slackware host is missing a security update.
File : Slackware_SSA_2011-070-01.nasl - Type : ACT_GATHER_INFO
2011-03-09 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2011-0327.nasl - Type : ACT_GATHER_INFO
2011-03-09 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2011-0328.nasl - Type : ACT_GATHER_INFO
2011-03-07 Name : The remote FreeBSD host is missing one or more security-related updates.
File : freebsd_pkg_e27ca763472111e0bdc4001e8c75030d.nasl - Type : ACT_GATHER_INFO
2011-03-07 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-2181.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2014-02-17 11:54:27
  • Multiple Updates