Family: Fedora Local Security Checks --> Category: infos
Fedora Core 1 2004-127: subversion Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the subversion package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory FEDORA-2004-127 (subversion).
Subversion is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a
hierarchy of files and directories while keeping a history of all
changes. Subversion only stores the differences between versions,
instead of every complete file. Subversion is intended to be a
compelling replacement for CVS.
Stefan Esser discovered an issue in the date parsing routines in
Subversion which allows a buffer overflow. A possible hacker could send
malicious requests to a Subversion server (either Apache-based using
mod_dav_svn, or using the svnserve daemon) and perform arbitrary
execution of code.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CVE-2004-0397 to this issue. This update includes
packages with a patch for this issue.
Solution : http://www.fedoranews.org/updates/FEDORA-2004-127.shtml
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.