Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.69755
Categoría:FreeBSD Local Security Checks
Título:FreeBSD Ports: subversion
Resumen:The remote host is missing an update to the system; as announced in the referenced advisory.
Descripción:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following packages are affected:

subversion
subversion-freebsd

CVE-2011-1752
The mod_dav_svn module for the Apache HTTP Server, as distributed in
Apache Subversion before 1.6.17, allows remote attackers to cause a
denial of service (NULL pointer dereference and daemon crash) via a
request for a baselined WebDAV resource, as exploited in the wild in
May 2011.
CVE-2011-1783
The mod_dav_svn module for the Apache HTTP Server, as distributed in
Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz
short_circuit option is enabled, allows remote attackers to cause a
denial of service (infinite loop and memory consumption) in
opportunistic circumstances by requesting data.
CVE-2011-1921
The mod_dav_svn module for the Apache HTTP Server, as distributed in
Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz
short_circuit option is disabled, does not properly enforce
permissions for files that had been publicly readable in the past,
which allows remote attackers to obtain sensitive information via a
replay REPORT operation.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-1752
http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html
BugTraq ID: 48091
http://www.securityfocus.com/bid/48091
Debian Security Information: DSA-2251 (Google Search)
http://www.debian.org/security/2011/dsa-2251
http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062211.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061913.html
http://www.mandriva.com/security/advisories?name=MDVSA-2011:106
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18922
http://www.redhat.com/support/errata/RHSA-2011-0861.html
http://www.redhat.com/support/errata/RHSA-2011-0862.html
http://www.securitytracker.com/id?1025617
http://secunia.com/advisories/44633
http://secunia.com/advisories/44681
http://secunia.com/advisories/44849
http://secunia.com/advisories/44879
http://secunia.com/advisories/44888
http://secunia.com/advisories/45162
http://www.ubuntu.com/usn/USN-1144-1
Common Vulnerability Exposure (CVE) ID: CVE-2011-1783
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18889
http://www.securitytracker.com/id?1025618
Common Vulnerability Exposure (CVE) ID: CVE-2011-1921
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18999
http://www.securitytracker.com/id?1025619
XForce ISS Database: subversion-control-rules-info-disc(67804)
https://exchange.xforce.ibmcloud.com/vulnerabilities/67804
CopyrightCopyright (c) 2011 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.