First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 51462
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Jani Averbach <jaa@jaa.iki.fi>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
condordes: ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 51462 depends on: Show dependency tree
Bug 51462 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-05-19 08:54 0000
From subversion 1.0.3 announce mail:
http://subversion.tigris.org/servlets/ReadMsg?list=announce&msgNo=125


Subversion versions up to and including 1.0.2 have a buffer overflow in
the date parsing code.

Both client and server are vulnerable.  The server is vulnerable over
both httpd/DAV and svnserve (that is, over http://, https://, svn://,
svn+ssh:// and other tunneled svn+*:// methods).

Additionally, clients with shared working copies, or permissions that
allow files in the administrative area of the working copy to be
written by other users, are potentially exploitable.


Reproducible: Always
Steps to Reproduce:





There is similar issue with up to and includind net-misc/neon-0.24.5
(CAN-2004-0398).
So, there is also update for neon (0.24.6), please see http://www.webdav.org/neon/.

------- Comment #1 From Thierry Carrez (RETIRED) 2004-05-19 09:00:22 0000 -------
*** Bug 51463 has been marked as a duplicate of this bug. ***

------- Comment #2 From Rajiv Aaron Manglani 2004-05-19 12:39:16 0000 -------
pauldv, please bump. thanks.

------- Comment #3 From Thierry Carrez (RETIRED) 2004-05-19 13:58:17 0000 -------
*** Bug 51491 has been marked as a duplicate of this bug. ***

------- Comment #4 From Thierry Carrez (RETIRED) 2004-05-19 14:00:28 0000 -------
Reassigning back to security so that we keep track of this one. Still waiting
for pauldv's bump.

------- Comment #5 From Andrew Cowie 2004-05-20 08:51:04 0000 -------
I'm raising a new bug for this, but FYI, subversion 1.0.4 is now available.
1.0.3 is the security fix.

http://subversion.tigris.org/project_status.html

AfC
Sydney

------- Comment #6 From Jani Averbach 2004-05-20 09:21:21 0000 -------
The new bug number for 1.0.4 is 51572
http://bugs.gentoo.org/show_bug.cgi?id=51572,

But, 1.0.4 isn't out yet (planned for tomorrow)!

------- Comment #7 From Thierry Carrez (RETIRED) 2004-05-20 10:04:11 0000 -------
Apparently 1.0.3 is in CVS. Stable flags are OK -- so it's ready for a GLSA

------- Comment #8 From Joshua J. Berry (CondorDes) (RETIRED) 2004-05-20 11:00:52 0000 -------
GLSA Drafted.

------- Comment #9 From Joshua J. Berry (CondorDes) (RETIRED) 2004-05-20 11:38:29 0000 -------
GLSA 200405-14.

First Last Prev Next    No search results available      Search page      Enter new bug