Advisories ยป MGASA-2015-0326

Updated subversion packages fix security vulnerabilities

Publication date: 27 Aug 2015
Type: security
Affected Mageia releases : 4 , 5
CVE: CVE-2015-3184 , CVE-2015-3187


Subversion's mod_authz_svn does not properly restrict anonymous access in some
mixed anonymous/authenticated environments when using Apache httpd 2.4.  The
result is that anonymous access may be possible to files for which only
authenticated access should be possible (CVE-2015-3184).

Subversion servers, both httpd and svnserve, will reveal some paths that
should be hidden by path-based authz.  When a node is copied from an
unreadable location to a readable location the unreadable path may be
revealed.  This vulnerablity only reveals the path, it does not reveal the
contents of the path (CVE-2015-3187).

This update also re-enables the java subpackage for the Mageia 5 subversion
package (mga#16075).