Fedora 20 : subversion-1.8.11-1.fc20 (2014-17222)

medium Nessus Plugin ID 80375


The remote Fedora host is missing a security update.


This update includes the latest stable release of **Apache Subversion**, version **1.8.11**. Two security issues in mod_dav_svn are addressed in this release (CVE-2014-8108, CVE-2014-3580). For more details, see :

http://subversion.apache.org/security/CVE-2014-8108-advisory.txt http://subversion.apache.org/security/CVE-2014-3580-advisory.txt

**Client-side bugfixes:**

- checkout/update: fix file externals failing to follow history and subsequently silently failing http://subversion.tigris.org/issues/show_bug.cgi?id=4185

- patch: don't skip targets in valid --git difs

- diff: make property output in diffs stable

- diff: fix diff of local copied directory with props

- diff: fix changelist filter for repos-WC and WC-WC

- remove broken conflict resolver menu options that always error out

- improve gpg-agent support

- fix crash in eclipse IDE with GNOME Keyring http://subversion.tigris.org/issues/show_bug.cgi?id=34 98

- fix externals shadowing a versioned directory http://subversion.tigris.org/issues/show_bug.cgi?id=40 85

- fix problems working on unix file systems that don't support permissions

- upgrade: keep external registrations http://subversion.tigris.org/issues/show_bug.cgi?id=45 19

- cleanup: iprove performance of recorded timestamp fixups

- translation updates for German

**Server-side bugfixes:**

- disable revprop caching feature due to cache invalidation problems

- skip generating uniquifiers if rep-sharing is not supported

- mod_dav_svn: reject requests with missing repository paths

- mod_dav_svn: reject requests with invalid virtual transaction names

- mod_dav_svn: avoid unneeded memory growth in resource walking http://subversion.tigris.org/issues/show_bug.cgi?id=45 31

Update the affected subversion package.

Plugin Details

Severity: Medium

ID: 80375

File Name: fedora_2014-17222.nasl

Version: 1.6

Type: local

Agent: unix

Published: 1/6/2015

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent

Risk Information


Risk Factor: Medium

Score: 4.4


Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Temporal Vector: E:U/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:subversion, cpe:/o:fedoraproject:fedora:20

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 12/18/2014

Reference Information

CVE: CVE-2014-3580, CVE-2014-8108

BID: 71725, 71726

FEDORA: 2014-17222