DSA-4490-1 subversion -- subversionID: oval:org.secpod.oval:def:69896 | Date: (C)2021-03-07 (M)2023-12-20 |
Class: PATCH | Family: unix |
Several vulnerabilities were discovered in Subversion, a version control system. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2018-11782 Ace Olszowka reported that the Subversion"s svnserve server process may exit when a well-formed read-only request produces a particular answer, leading to a denial of service. CVE-2019-0203 Tomas Bortoli reported that the Subversion"s svnserve server process may exit when a client sends certain sequences of protocol commands. If the server is configured with anonymous access enabled this could lead to a remote unauthenticated denial of service.