subversion:1.14 security update
エラータID: AXSA:2022-3792:01
リリース日:
2022/09/05 Monday - 07:14
題名:
subversion:1.14 security update
影響のあるチャネル:
Asianux Server 8 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- subversion には、mod_dav_svn のパスベースの認証ルール
検索処理において解放後メモリ参照の脆弱性があります。
(CVE-2022-24070)
Modularity name: subversion
Stream name: 1.14
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2022-24070
Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do not use mod_dav_svn are not affected.
Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do not use mod_dav_svn are not affected.
追加情報:
N/A
ダウンロード:
SRPMS
- libserf-1.3.9-9.module+el8+1514+17aa663c.src.rpm
MD5: 89491592bae4e443e79199747ce83554
SHA-256: 5741e7f7cc7fd092a02920a0aefbe7e4f2d524dbae884faa9e84b06c6a2b2f5a
Size: 154.45 kB - subversion-1.14.1-2.module+el8+1514+17aa663c.src.rpm
MD5: 60af081ceee3a98817dae5478b079625
SHA-256: 875e05194c3cbd946a5f8edd0e0459c0d917f0782a9ff682013c90a18db256a8
Size: 8.20 MB - utf8proc-2.1.1-5.module+el8+1514+17aa663c.src.rpm
MD5: d28e347857cd187aa1ddd2754290aa48
SHA-256: 26eed149669135b6f1fb1e41e875f3826fa410be0832201e67499f292ffc4873
Size: 148.80 kB
Asianux Server 8 for x86_64
- libserf-1.3.9-9.module+el8+1514+17aa663c.x86_64.rpm
MD5: f0c02927a07582fedd1a093f7b03562c
SHA-256: 9d16db017327f21e05bd68a1e5b34f233a44596db0f94da3325ea1bedf77f75b
Size: 58.39 kB - libserf-debugsource-1.3.9-9.module+el8+1514+17aa663c.x86_64.rpm
MD5: 73e69da036ed31542694818d413d4825
SHA-256: e1f944030db1d07e23d27507ba3c15d68b6f7e32c73477a30e270ec40e09a013
Size: 98.56 kB - mod_dav_svn-1.14.1-2.module+el8+1514+17aa663c.x86_64.rpm
MD5: 674a747db7d0445ccd89e0a00b96c957
SHA-256: ac4cf31c4ba203436586959ba361a8b346f90281e7854b592bc725e0b97f7c83
Size: 108.90 kB - python3-subversion-1.14.1-2.module+el8+1514+17aa663c.x86_64.rpm
MD5: f11a81e0a2fb005cad71e039334ff293
SHA-256: 07d933fdc8776af6994246d976621151252f71438da3706af704b67f28e23fd1
Size: 842.24 kB - subversion-1.14.1-2.module+el8+1514+17aa663c.x86_64.rpm
MD5: e5db39a1f30e651febe260a610c5d206
SHA-256: d912e4338121fb2c30da08a3ff88d91f4041fde2b4bc8bb6e0a1cb1e672e574b
Size: 1.13 MB - subversion-debugsource-1.14.1-2.module+el8+1514+17aa663c.x86_64.rpm
MD5: 0e91642076291a5f58f303aea8808d48
SHA-256: 13d9f8844998f143c0809fdb2d203d67eeee94339e415d72914678f5153ea7a0
Size: 3.50 MB - subversion-devel-1.14.1-2.module+el8+1514+17aa663c.x86_64.rpm
MD5: 0a133fbab6e6ab33f9c67216ba0b77a0
SHA-256: 9c3df098b3f2a483003cb30027179f9524a295bed1fd9c1904f58055301af8f7
Size: 347.41 kB - subversion-gnome-1.14.1-2.module+el8+1514+17aa663c.x86_64.rpm
MD5: 8874c9edd0bcaebe7f2179b32b8c7239
SHA-256: c53308c18104cbc61a334ff56e94a47efd2c933c9acdd2efd37352460e186cb4
Size: 25.73 kB - subversion-javahl-1.14.1-2.module+el8+1514+17aa663c.noarch.rpm
MD5: 87f52526de29753890a24e9df4574191
SHA-256: b474ef16ba7521d21f5b45820d9763eb9944654bab2ecb20bc2b530741f540a6
Size: 404.33 kB - subversion-libs-1.14.1-2.module+el8+1514+17aa663c.x86_64.rpm
MD5: 5277bff62842f43f464e1991bd999347
SHA-256: cb5cf948f7f8b79406905ef95104129ac2f14bb7d5b61aa1974c8a0d3c8d92a9
Size: 1.54 MB - subversion-perl-1.14.1-2.module+el8+1514+17aa663c.x86_64.rpm
MD5: 210e428ff01beb25f5cc3533fe4d606e
SHA-256: 5f78e06089c0d6842c1f41436be355b67b8ef9c5745bb2bee0826c58a46b0b98
Size: 0.97 MB - subversion-tools-1.14.1-2.module+el8+1514+17aa663c.x86_64.rpm
MD5: 2317137202561190869aa507cd4a81ce
SHA-256: c8fbdcd99817ee2fdf04e828f45998a5cd42fa45e5940029d7ceefe542c0f0e6
Size: 221.19 kB - utf8proc-2.1.1-5.module+el8+1514+17aa663c.x86_64.rpm
MD5: 6078b380577cae4d153538a7c774a423
SHA-256: 33169f3b71744272ca47f54a55bef72c71fbdc90144fadfb12a909c458a32218
Size: 65.69 kB - utf8proc-debugsource-2.1.1-5.module+el8+1514+17aa663c.x86_64.rpm
MD5: 5d2fbb57d61c49b7a7e2211dfc1ecdeb
SHA-256: cf59b75bff085acea0ec795fee2068156b5903271bfa21bc0392fefce3262c69
Size: 79.49 kB