Debian Security Advisory
DSA-3932-1 subversion -- security update
- Date Reported:
- 10 Aug 2017
- Affected Packages:
- subversion
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2016-8734, CVE-2017-9800.
- More information:
-
Several problems were discovered in Subversion, a centralised version control system.
- CVE-2016-8734
(jessie only)
Subversion's mod_dontdothat server module and Subversion clients using http(s):// were vulnerable to a denial-of-service attack caused by exponential XML entity expansion.
- CVE-2017-9800
Joern Schneeweisz discovered that Subversion did not correctly handle maliciously constructed svn+ssh:// URLs. This allowed an attacker to run an arbitrary shell command, for instance via svn:externals properties or when using
svnsync sync
.
For the oldstable distribution (jessie), these problems have been fixed in version 1.8.10-6+deb8u5.
For the stable distribution (stretch), these problems have been fixed in version 1.9.5-1+deb9u1.
We recommend that you upgrade your subversion packages.
- CVE-2016-8734