SB2014030711 - Input validation error in subversion (Alpine package)
Published: March 7, 2014
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2013-4558)
The vulnerability allows a remote #AU# to perform service disruption.
The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request, as demonstrated using a trailing /.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=6d009de01b5f285b023c73ae643bfaaa0435e5af
- https://git.alpinelinux.org/aports/commit/?id=48505d9504858193f17f61dde0799de9dfff7c6c
- https://git.alpinelinux.org/aports/commit/?id=ddb14202fd187cde4f1bd4c5ffe322364b71eaa9
- https://git.alpinelinux.org/aports/commit/?id=856ed3ee75cfe016fe76d83c1929d05ea7e09763