Debian Security Advisory

DSA-3932-1 subversion -- security update

Date Reported:
10 Aug 2017
Affected Packages:
Security database references:
In Mitre's CVE dictionary: CVE-2016-8734, CVE-2017-9800.
More information:

Several problems were discovered in Subversion, a centralised version control system.

  • CVE-2016-8734

    (jessie only)

    Subversion's mod_dontdothat server module and Subversion clients using http(s):// were vulnerable to a denial-of-service attack caused by exponential XML entity expansion.

  • CVE-2017-9800

    Joern Schneeweisz discovered that Subversion did not correctly handle maliciously constructed svn+ssh:// URLs. This allowed an attacker to run an arbitrary shell command, for instance via svn:externals properties or when using svnsync sync.

For the oldstable distribution (jessie), these problems have been fixed in version 1.8.10-6+deb8u5.

For the stable distribution (stretch), these problems have been fixed in version 1.9.5-1+deb9u1.

We recommend that you upgrade your subversion packages.