USN-1096-1: Subversion vulnerability

Publication date

29 March 2011

Overview

An attacker could send crafted input to the Subversion mod_dav_svn module for Apache and cause it to crash.


Packages

Details

Philip Martin discovered that the Subversion mod_dav_svn module for Apache
did not properly handle certain requests containing a lock token. A remote
attacker could use this flaw to cause the service to crash, leading to a
denial of service.

Philip Martin discovered that the Subversion mod_dav_svn module for Apache
did not properly handle certain requests containing a lock token. A remote
attacker could use this flaw to cause the service to crash, leading to a
denial of service.

Update instructions

After a standard system update you need to restart any applications that use Subversion, such as Apache when using mod_dav_svn, to make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
9.10 karmic libapache2-svn –  1.6.5dfsg-1ubuntu1.2
8.04 hardy libapache2-svn –  1.4.6dfsg1-2ubuntu1.3
6.06 dapper libapache2-svn –  1.3.1-3ubuntu1.4
10.10 maverick libapache2-svn –  1.6.12dfsg-1ubuntu1.2
10.04 lucid libapache2-svn –  1.6.6dfsg-2ubuntu1.2

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›