Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Apache Subversion < 1.8.0 / 1.7.10 / 1.6.23 Multiple Vulnerabilities

Medium

Synopsis

The remote host is running a version of Apache Subversion that is vulnerable to multiple attack vectors. Subversion is an open-source version-control application that is available for numerous platforms, including Microsoft Windows, UNIX, and UNIX-like operating systems.

Description

The installed version of SVN is affected by the following vulnerabilities:

- Remote denial-of-service vulnerabilities exist due to an error in the svnserve server, as it does not properly handle aborted connection messages. (CVE-2013-1968, CVE-2013-2112)

- A command-injection vulnerability exists in the 'svn-keyword-check.pl' hook script while processing filenames. (CVE-2013-2088)

Solution

Updates are available. Alternatively, upgrade to versions 1.8.0, 1.7.10, or 1.6.23.