http://www.mandriva.com/en/
______________________________
Package : subversion
Date : September 2, 2014
Affected: Business Server 1.0
______________________________
Problem Description:
Updated subversion packages fix security vulnerability:
Bert Huijben discovered that Subversion did not properly handle
cached credentials. A malicious server could possibly use this issue
to obtain credentials cached for a different server (CVE-2014-3528).
______________________________
References:
http://cve.mitre.org/cgi-bin/
http://advisories.mageia.org/
______________________________
Updated Packages:
Mandriva Business Server 1/X86_64:
bff94b4e4e824974e46de8479ade18
58326f310ce3494f20282afc19ed40
fa40f52b246ae493e6440852ed70b3
103acf16dd9692d7f4e14959ff8aff
f32ac961da41597fa3d4f24439baa9
1b2377acf97ac1ae29c1d32ec9ef64
e3c458d6e08d88f842acee45f3b44c
0b513c377e565bcb5937e4eb082398
e2c18cbc444edd590721ae25d8ad43
ea8a558b8377632a392ce725523617
c91b30c1e098755035c4e4c22feb8e
67cfade102c99c9d6132f79704e57c
b2c398deadbfac328f4877b2d327fd
2351edb7943867504f2b504f1c0229
49e98012f5fa91b2c80c9644101989
baf8bcb91630989fd4184160f87feb
e73e0d9050b45af13591670c97caa9
93bb920b95f39679ba014da195bc62
______________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Komentarų nėra:
Rašyti komentarą