SB2014030712 - Input validation error in subversion (Alpine package)
Published: March 7, 2014
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2014-0032)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The get_resource function in repos.c in the mod_dav_svn module in Apache Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is enabled, allows remote attackers to cause a denial of service (crash) via vectors related to the server root and request methods other than GET, as demonstrated by the "svn ls http://svn.example.com" command.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=6d009de01b5f285b023c73ae643bfaaa0435e5af
- https://git.alpinelinux.org/aports/commit/?id=48505d9504858193f17f61dde0799de9dfff7c6c
- https://git.alpinelinux.org/aports/commit/?id=ddb14202fd187cde4f1bd4c5ffe322364b71eaa9
- https://git.alpinelinux.org/aports/commit/?id=856ed3ee75cfe016fe76d83c1929d05ea7e09763