Debian Security Advisory
DSA-3424-1 subversion -- security update
- Date Reported:
- 16 Dec 2015
- Affected Packages:
- subversion
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2015-5343.
- More information:
-
Ivan Zhakov discovered an integer overflow in mod_dav_svn, which allows an attacker with write access to the server to execute arbitrary code or cause a denial of service.
The oldstable distribution (wheezy) is not affected.
For the stable distribution (jessie), this problem has been fixed in version 1.8.10-6+deb8u2.
For the unstable distribution (sid), this problem has been fixed in version 1.9.3-1.
We recommend that you upgrade your subversion packages.