SB2017010312 - Fedora 25 update for subversion



SB2017010312 - Fedora 25 update for subversion

Published: January 3, 2017 Updated: April 24, 2025

Security Bulletin ID SB2017010312
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Resource exhaustion (CVE-ID: CVE-2016-8734)

The vulnerability allows a remote authenticated user to perform a denial of service (DoS) attack.

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.


Remediation

Install update from vendor's website.