subversion-1.6.11-2.AXS4.2

エラータID: AXSA:2011-60:01

リリース日: 
2011/02/24 Thursday - 13:30
題名: 
subversion-1.6.11-2.AXS4.2
影響のあるチャネル: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

Subversion is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes. Subversion only stores the differences between versions, instead of every complete file. Subversion is intended to be a compelling replacement for CVS.
Security issues fixed with this release:
CVE-2010-3315
authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.
CVE-2010-4539
The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.15, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger the walking of SVNParentPath collections.
CVE-2010-4644
Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. subversion-1.6.11-2.AXS4.2.src.rpm
    MD5: 4659700d958114c716a0ae634ac429d8
    SHA-256: 96dccbd66724d5dcdf6a5cda0636cfe71f096003882c60ff5d10d0ebbc70af6e
    Size: 5.33 MB

Asianux Server 4 for x86
  1. mod_dav_svn-1.6.11-2.AXS4.2.i686.rpm
    MD5: dd792f29ac5b53feab5c70cee0220e22
    SHA-256: 6adb4ce52aaad7712ad5a71c6c844e8d5600e0608c6eec78e6de0ae6de6ca039
    Size: 78.67 kB
  2. subversion-1.6.11-2.AXS4.2.i686.rpm
    MD5: 653d9f2df9469a320a77f66a4fb981a3
    SHA-256: 2302013bd4f7b1fd339d83d101c0a2c3903ccd8674e6c8ee8d373d951bfd7d4a
    Size: 2.23 MB
  3. subversion-javahl-1.6.11-2.AXS4.2.i686.rpm
    MD5: 4e82bf10946f6341285666c9519db01d
    SHA-256: 039ef0f9da3f8a8b999464ac7c4382c18b42cc012af52ae4a3610ab64ab2754e
    Size: 171.01 kB

Asianux Server 4 for x86_64
  1. mod_dav_svn-1.6.11-2.AXS4.2.x86_64.rpm
    MD5: 1286b18a927392438e6441f745435baf
    SHA-256: 1614574ebae8eae2820aca552121419258fd860a8f2a29056dc2d37df81be092
    Size: 77.36 kB
  2. subversion-1.6.11-2.AXS4.2.x86_64.rpm
    MD5: 968979b4bcdc35034e61f109cbb984c6
    SHA-256: 48f1b521385d472a56e9b37246f0e174e36634951a72772e9080f759b706880a
    Size: 2.28 MB
  3. subversion-javahl-1.6.11-2.AXS4.2.x86_64.rpm
    MD5: 1c2dadb56cfa9edace7346439a481bff
    SHA-256: 137d96f34fa6aac9d16e63d91bd16c7cd2fa003a0917e0f5ad0b6d9deae5bd02
    Size: 171.80 kB
  4. subversion-1.6.11-2.AXS4.2.i686.rpm
    MD5: 653d9f2df9469a320a77f66a4fb981a3
    SHA-256: 2302013bd4f7b1fd339d83d101c0a2c3903ccd8674e6c8ee8d373d951bfd7d4a
    Size: 2.23 MB
  5. subversion-javahl-1.6.11-2.AXS4.2.i686.rpm
    MD5: 4e82bf10946f6341285666c9519db01d
    SHA-256: 039ef0f9da3f8a8b999464ac7c4382c18b42cc012af52ae4a3610ab64ab2754e
    Size: 171.01 kB