LWN.net Logo

subversion: restriction bypass

Package(s):subversion CVE #(s):CVE-2010-3315
Created:October 11, 2010 Updated:February 16, 2011
Description: From the Debian advisory:

Kamesh Jayachandran and C. Michael Pilat discovered that the mod_dav_svn module of subversion, a version control system, is not properly enforcing access rules which are scope-limited to named repositories. If the SVNPathAuthz option is set to "short_circuit" set this may enable an unprivileged attacker to bypass intended access restrictions and disclose or modify repository content.

Alerts:
Red Hat RHSA-2011:0258-01 2011-02-15
Ubuntu USN-1053-1 2011-02-01
SUSE SUSE-SR:2010:024 2010-12-23
openSUSE openSUSE-SU-2010:1042-1 2010-12-10
Fedora FEDORA-2010-16115 2010-10-11
Fedora FEDORA-2010-16136 2010-10-11
Mandriva MDVSA-2010:199 2010-10-12
Debian DSA-2118-1 2010-10-08

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds