Mandriva Linux Security Advisory MDVSA-2015:005
http://www.mandriva.com/en/
______________________________
Package : subversion
Date : January 5, 2015
Affected: Business Server 1.0
______________________________
Problem Description:
Updated subversion packages fix security vulnerabilities:
A NULL pointer dereference flaw was found in the way mod_dav_svn
handled REPORT requests. A remote, unauthenticated attacker could
use a crafted REPORT request to crash mod_dav_svn (CVE-2014-3580).
A NULL pointer dereference flaw was found in the way mod_dav_svn
handled URIs for virtual transaction names. A remote, unauthenticated
attacker could send a request for a virtual transaction name that
does not exist, causing mod_dav_svn to crash (CVE-2014-8108).
______________________________
References:
http://cve.mitre.org/cgi-bin/
http://cve.mitre.org/cgi-bin/
http://advisories.mageia.org/
______________________________
Updated Packages:
Mandriva Business Server 1/X86_64:
1f354ed65a056a0b70d9d2be13b029
3ae0fad77ef662db9cc15593e6b3e1
086f52b7c9c2613a9dfdc2edd6456b
08502b3288cb52bbdcad5e1de62d7d
1b9e41016558998ccbf885a9d903ef
24e7f603b2d9fa85e74688410a653c
ab734f1e83a67fc462ad73c1dd9977
1fa42a41ed0d14e925e22ebaae5e45
3a9e6f623b9d56c101105bebb94482
3226dac8aba329eb3ce55da46f876b
4bedf492fa0684cdb22594e2699451
93e03dc4a459ce77bc7f9a597ecdd0
2f9467b156e9a560d06873eb0add58
cb884252dd565d2df29645d7ab7847
d23255839ec971356cdcf831ee5923
574b474f2eb518e0326f8975c354f1
a4002b39cd679324b1b3274db3c415
64428cd0f639f7ec9dd033c04823f0
______________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Komentarų nėra:
Rašyti komentarą