USN-3388-2: Subversion vulnerabilities
USN-3388-2: Subversion vulnerabilities Ubuntu Security Notice USN-3388-2 24th October, 2017 subversion vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Several security issues were fixed in Subversion. Software description subversion – Advanced version control system Details USN-3388-1 fixed several vulnerabilities in Subversion. This updateprovides the corresponding update for Ubuntu 12.04 ESM. Ivan Zhakov discovered that Subversion did not properly handlesome requests. A remote attacker could use this to cause adenial of service. (CVE-2016-2168) Original advisory details: Joern Schneeweisz discovered that Subversion did not properly handle host names in 'svn+ssh://' URLs. A remote attacker could use this to construct a subversion repository that when accessed could run arbitrary code with the privileges of the user. (CVE-2017-9800) Daniel Shahaf and James McCoy discovered that Subversion did not properly verify realms when using Cyrus SASL authentication. [ more… ]