You are here
Home > Preporuke > Sigurnosni propust programskog paketa subversion

Sigurnosni propust programskog paketa subversion

  • Detalji os-a: LMV
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LMV

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2014:161
http://www.mandriva.com/en/support/security/
_______________________________________________________________________

Package : subversion
Date : September 2, 2014
Affected: Business Server 1.0
_______________________________________________________________________

Problem Description:

Updated subversion packages fix security vulnerability:

Bert Huijben discovered that Subversion did not properly handle
cached credentials. A malicious server could possibly use this issue
to obtain credentials cached for a different server (CVE-2014-3528).
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3528
http://advisories.mageia.org/MGASA-2014-0338.html
_______________________________________________________________________

Updated Packages:

Mandriva Business Server 1/X86_64:
bff94b4e4e824974e46de8479ade18cb mbs1/x86_64/apache-mod_dav_svn-1.7.18-1.mbs1.x86_64.rpm
58326f310ce3494f20282afc19ed4061 mbs1/x86_64/lib64svn0-1.7.18-1.mbs1.x86_64.rpm
fa40f52b246ae493e6440852ed70b32f mbs1/x86_64/lib64svn-gnome-keyring0-1.7.18-1.mbs1.x86_64.rpm
103acf16dd9692d7f4e14959ff8aff4e mbs1/x86_64/lib64svnjavahl1-1.7.18-1.mbs1.x86_64.rpm
f32ac961da41597fa3d4f24439baa9e3 mbs1/x86_64/perl-SVN-1.7.18-1.mbs1.x86_64.rpm
1b2377acf97ac1ae29c1d32ec9ef646d mbs1/x86_64/perl-svn-devel-1.7.18-1.mbs1.x86_64.rpm
e3c458d6e08d88f842acee45f3b44cd6 mbs1/x86_64/python-svn-1.7.18-1.mbs1.x86_64.rpm
0b513c377e565bcb5937e4eb0823987d mbs1/x86_64/python-svn-devel-1.7.18-1.mbs1.x86_64.rpm
e2c18cbc444edd590721ae25d8ad432e mbs1/x86_64/ruby-svn-1.7.18-1.mbs1.x86_64.rpm
ea8a558b8377632a392ce7255236171c mbs1/x86_64/ruby-svn-devel-1.7.18-1.mbs1.x86_64.rpm
c91b30c1e098755035c4e4c22feb8e40 mbs1/x86_64/subversion-1.7.18-1.mbs1.x86_64.rpm
67cfade102c99c9d6132f79704e57c92 mbs1/x86_64/subversion-devel-1.7.18-1.mbs1.x86_64.rpm
b2c398deadbfac328f4877b2d327fd34 mbs1/x86_64/subversion-doc-1.7.18-1.mbs1.x86_64.rpm
2351edb7943867504f2b504f1c0229eb mbs1/x86_64/subversion-gnome-keyring-devel-1.7.18-1.mbs1.x86_64.rpm
49e98012f5fa91b2c80c9644101989e2 mbs1/x86_64/subversion-server-1.7.18-1.mbs1.x86_64.rpm
baf8bcb91630989fd4184160f87feb40 mbs1/x86_64/subversion-tools-1.7.18-1.mbs1.x86_64.rpm
e73e0d9050b45af13591670c97caa904 mbs1/x86_64/svn-javahl-1.7.18-1.mbs1.x86_64.rpm
93bb920b95f39679ba014da195bc6237 mbs1/SRPMS/subversion-1.7.18-1.mbs1.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg –recv-keys –keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/en/support/security/advisories/

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.12 (GNU/Linux)

iD8DBQFUBaOGmqjQ0CJFipgRAk32AKDCwQsio9x3WrZnKNy1MOf5LDvJ3gCgtS3Q
ct3IdlMq1mqCiZSzQ2T4hcg=
=M9D+
—–END PGP SIGNATURE—–

To unsubscribe, send a email to sympa@mandrivalinux.org
with this subject : unsubscribe security-announce
_______________________________________________________
Want to buy your Pack or Services from Mandriva?
Go to http://store.mandriva.com
_______________________________________________________

AutorTomislav Protega
Cert idNCERT-REF-2014-09-0006-ADV
CveCVE-2014-3528
ID izvornikaMDVSA-2014:161
Proizvodsubversion
Izvorhttp://www.mandriva.com
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa python-imaging

Otkriven je sigurnosni nedostatak u programskom paketu python-imaging za operacijski sustav Mandriva. Otkriveni nedostatak potencijalnim napadačima omogućuje izvođenje napada uskraćivanja...

Close