Advisories ยป MGASA-2014-0545

Updated subversion packages fix security vulnerabilities

Publication date: 23 Dec 2014
Modification date: 23 Dec 2014
Type: security
Affected Mageia releases : 4
CVE: CVE-2014-3580 , CVE-2014-8108

Description

A NULL pointer dereference flaw was found in the way mod_dav_svn handled
REPORT requests. A remote, unauthenticated attacker could use a crafted
REPORT request to crash mod_dav_svn (CVE-2014-3580).

A NULL pointer dereference flaw was found in the way mod_dav_svn handled URIs
for virtual transaction names. A remote, unauthenticated attacker could send
a request for a virtual transaction name that does not exist, causing
mod_dav_svn to crash (CVE-2014-8108).
                

References

SRPMS

4/core