[SECURITY] Fedora Core 1 Update: subversion-0.32.1-2

Joe Orton jorton at redhat.com
Wed May 19 16:17:25 UTC 2004


---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-127
2004-05-19
---------------------------------------------------------------------

Product     : Fedora Core 1
Name        : subversion
Version     : 0.32.1                      
Release     : 2                  
Summary     : A Concurrent Versioning system similar to, but better than, CVS.
Description :
Subversion is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a
hierarchy of files and directories while keeping a history of all
changes.  Subversion only stores the differences between versions,
instead of every complete file.  Subversion is intended to be a
compelling replacement for CVS.

---------------------------------------------------------------------
Update Information:

Stefan Esser discovered an issue in the date parsing routines in
Subversion which allows a buffer overflow.  An attacker could send
malicious requests to a Subversion server (either Apache-based using
mod_dav_svn, or using the svnserve daemon) and perform arbitrary
execution of code.  

The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-0397 to this issue.  This update includes
packages with a patch for this issue.

---------------------------------------------------------------------
* Wed May 12 2004 Joe Orton <jorton at redhat.com> 0.32.1-2

- add security fix for CVE CAN-2004-0397 (Ben Reser)

---------------------------------------------------------------------
This update can be downloaded from:
  http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

21f86e755d58ec2ca68c2dc338e26743  SRPMS/subversion-0.32.1-2.src.rpm
e844f7f47bdae053bfe94d4b0fd2ee16  i386/subversion-0.32.1-2.i386.rpm
18413a741fb6a6ffac48b3765bb0dd6d  i386/subversion-devel-0.32.1-2.i386.rpm
8565cf933e01213c9cfd741e66fb49d9  i386/mod_dav_svn-0.32.1-2.i386.rpm
04be62fe37bf0a0af958f4dba83dc717  i386/debug/subversion-debuginfo-0.32.1-2.i386.rpm
fc9cec597b0ac29f8af2311059c0325a  x86_64/subversion-0.32.1-2.x86_64.rpm
69617e64446f47824698ffd94cb3f01b  x86_64/subversion-devel-0.32.1-2.x86_64.rpm
903b1f372340c0099ee7876175b3dc23  x86_64/mod_dav_svn-0.32.1-2.x86_64.rpm
0f4755e17c255b54dfdd9c9982d52910  x86_64/debug/subversion-debuginfo-0.32.1-2.x86_64.rpm

This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.  
---------------------------------------------------------------------


-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/fedora-announce-list/attachments/20040519/358fc98e/attachment.sig>


More information about the fedora-announce-list mailing list