** Please note that this issue is confidential and no information should be disclosed until it is made public, see "Whiteboard" for a date ** Hyrum K. Wright informed us about this vulnerablility in Subversion: =========================================================================== Subversion clients and servers up to 1.6.3 (inclusive) have heap overflow issues in the parsing of binary deltas. Summary: ======== Subversion clients and servers have multiple heap overflow issues in the parsing of binary deltas. This is related to an allocation vulnerability in the APR library used by Subversion. Clients with commit access to a vulnerable server can cause a remote heap overflow; servers can cause a heap overflow on vulnerable clients that try to do a checkout or update. This can lead to a DoS (an exploit has been tested) and to arbitrary code execution (no exploit tested, but the possibility is clear).
An updated ebuild is being prepared, we'll prestable after that. As usual, no commits to CVS please.
Created attachment 200289 [details] subversion-1.6.4.ebuild
Created attachment 200290 [details] subversion-1.6.4-r10.ebuild
The tarball can be downloaded from https://orac.ece.utexas.edu/pub/svn/1.6.4/ Username: svn Password: KEnuprE3
Arch Security Liaisons, please test the attached ebuild and report it stable on this bug. Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86" CC'ing current Liaisons: alpha : armin76, klausman amd64 : keytoaster, tester hppa : jer ppc : josejx, ranger ppc64 : josejx, ranger sparc : fmccor x86 : fauli, maekke
Comment on attachment 200290 [details] subversion-1.6.4-r10.ebuild Target is -r0.
in case it is not clear from above, the distfile can be fetched via wget --no-check-certificate https://svn:KEnuprE3@orac.ece.utexas.edu/pub/svn/1.6.4/moonlight/to-tigris/subversion-1.6.4.tar.bz2 Please handle this ASAP. Also cc'ing Kurt and Robin from infra.
amd64 ok
x86 looks ok to (the same tests fail as in the previous version)
HPPA is OK.
Public via $URL. Arches: Please allow me to reiterate the urgency of this bug.
dev-util/subversion-1.6.4{,-r10} is now in the tree.
ppc64 done
CVE-2009-2411 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2411): Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.
ppc stable
alpha/arm/ia64/s390/sh/sparc stable
GLSA request filed.
GLSA 200908-05