UbuntuUpdates.org

Bugs fixes in "subversion"

Origin Bug number Title Date fixed
CVE CVE-2016-8734 Unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s):// 2017-08-11
CVE CVE-2016-2168 The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote 2017-08-11
CVE CVE-2016-2167 The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication 2017-08-11
CVE CVE-2017-9800 Arbitrary code execution on clients through malicious svn+ssh URLs in svn:externals and svn:sync-from-url 2017-08-11
CVE CVE-2015-5343 Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users t 2017-08-11
CVE CVE-2016-8734 Unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s):// 2017-08-11
CVE CVE-2016-2168 The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote 2017-08-11
CVE CVE-2016-2167 The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication 2017-08-11
CVE CVE-2017-9800 Arbitrary code execution on clients through malicious svn+ssh URLs in svn:externals and svn:sync-from-url 2017-08-11
CVE CVE-2016-8734 Unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s):// 2017-08-11
CVE CVE-2016-2168 The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote 2017-08-11
CVE CVE-2016-2167 The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication 2017-08-11
CVE CVE-2017-9800 Arbitrary code execution on clients through malicious svn+ssh URLs in svn:externals and svn:sync-from-url 2017-08-11
CVE CVE-2016-8734 Unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s):// 2017-08-11
CVE CVE-2016-2168 The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote 2017-08-11
CVE CVE-2016-2167 The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication 2017-08-11
CVE CVE-2017-9800 Arbitrary code execution on clients through malicious svn+ssh URLs in svn:externals and svn:sync-from-url 2017-08-11
CVE CVE-2015-3187 The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows 2015-08-20
CVE CVE-2015-0251 The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property 2015-08-20
CVE CVE-2015-0248 The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of 2015-08-20



About   -   Send Feedback to @ubuntu_updates