USN-3388-1: Subversion vulnerabilities
USN-3388-1: Subversion vulnerabilities Ubuntu Security Notice USN-3388-1 11th August, 2017 subversion vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Subversion. Software description subversion – Advanced version control system Details Joern Schneeweisz discovered that Subversion did not properly handlehost names in 'svn+ssh://' URLs. A remote attacker could use thisto construct a subversion repository that when accessed could runarbitrary code with the privileges of the user. (CVE-2017-9800) Daniel Shahaf and James McCoy discovered that Subversion did notproperly verify realms when using Cyrus SASL authentication. Aremote attacker could use this to possibly bypass intended accessrestrictions. This issue only affected Ubuntu 14.04 LTS and Ubuntu16.04 LTS. (CVE-2016-2167) Florian Weimer discovered that Subversion clients did not properlyrestrict XML entity expansion when accessing http(s):// URLs. A remoteattacker [ more… ]