Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.881711
Categoría:CentOS Local Security Checks
Título:CentOS Update for mod_dav_svn CESA-2013:0737 centos6
Resumen:The remote host is missing an update for the 'mod_dav_svn'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'mod_dav_svn'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access to
Subversion repositories via HTTP.

A NULL pointer dereference flaw was found in the way the mod_dav_svn module
handled PROPFIND requests on activity URLs. A remote attacker could use
this flaw to cause the httpd process serving the request to crash.
(CVE-2013-1849)

A flaw was found in the way the mod_dav_svn module handled large numbers
of properties (such as those set with the 'svn propset' command). A
malicious, remote user could use this flaw to cause the httpd process
serving the request to consume an excessive amount of system memory.
(CVE-2013-1845)

Two NULL pointer dereference flaws were found in the way the mod_dav_svn
module handled LOCK requests on certain types of URLs. A malicious, remote
user could use these flaws to cause the httpd process serving the request
to crash. (CVE-2013-1846, CVE-2013-1847)

Note: The CVE-2013-1849, CVE-2013-1846, and CVE-2013-1847 issues only
caused a temporary denial of service, as the Apache HTTP Server started a
new process to replace the crashed child process. When using prefork MPM,
the crash only affected the attacker. When using worker (threaded) MPM, the
connections of other users may have been interrupted.

Red Hat would like to thank the Apache Subversion project for reporting
these issues. Upstream acknowledges Alexander Klink as the original
reporter of CVE-2013-1845, Ben Reser as the original reporter of
CVE-2013-1846, and Philip Martin and Ben Reser as the original reporters of
CVE-2013-1847.

All subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, you must restart the httpd daemon, if you are using
mod_dav_svn, for the update to take effect.

Affected Software/OS:
mod_dav_svn on CentOS 6

Solution:
Please install the updated packages.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2013-1845
http://www.mandriva.com/security/advisories?name=MDVSA-2013:153
http://mail-archives.apache.org/mod_mbox/subversion-announce/201304.mbox/%3CCADkdwvRoyVrZV12tgC0FMGrc6%2BMisd3qTcZ%2BDdpFGgTahkgAkQ%40mail.gmail.com%3E
http://mail-archives.apache.org/mod_mbox/subversion-announce/201304.mbox/%3CCADkdwvSTMLbn4q_KM3Ph2UOeSiPGhEK4%3DSvwEjaHW_GUGkYWPQ%40mail.gmail.com%3E
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18973
RedHat Security Advisories: RHSA-2013:0737
http://rhn.redhat.com/errata/RHSA-2013-0737.html
SuSE Security Announcement: openSUSE-SU-2013:0687 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-04/msg00095.html
SuSE Security Announcement: openSUSE-SU-2013:0932 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-06/msg00069.html
http://www.ubuntu.com/usn/USN-1893-1
Common Vulnerability Exposure (CVE) ID: CVE-2013-1846
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18087
Common Vulnerability Exposure (CVE) ID: CVE-2013-1847
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18538
Common Vulnerability Exposure (CVE) ID: CVE-2013-1849
http://seclists.org/fulldisclosure/2013/Mar/56
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18980
CopyrightCopyright (c) 2013 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.