This script is Copyright (C) 2017 Tenable Network Security, Inc.
The remote Red Hat host is missing one or more security updates.
An update for subversion is now available for Red Hat Enterprise Linux
Red Hat Product Security has rated this update as having a security
impact of Important. A Common Vulnerability Scoring System (CVSS) base
score, which gives a detailed severity rating, is available for each
vulnerability from the CVE link(s) in the References section.
Subversion (SVN) is a concurrent version control system which enables
one or more users to collaborate in developing and maintaining a
hierarchy of files and directories while keeping a history of all
Security Fix(es) :
* A shell command injection flaw related to the handling of 'svn+ssh'
URLs has been discovered in Subversion. An attacker could use this
flaw to execute shell commands with the privileges of the user running
the Subversion client, for example when performing a 'checkout' or
'update' action on a malicious repository, or a legitimate repository
containing a malicious commit. (CVE-2017-9800)
Red Hat would like to thank the Subversion Team for reporting this
See also :
Update the affected packages.
Risk factor :
High / CVSS Base Score : 7.5
CVSS Temporal Score : 6.2
Public Exploit Available : true