SB2014030710 - Permissions, Privileges, and Access Controls in subversion (Alpine package)
Published: March 7, 2014
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2013-4505)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL in a REPORT request.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=6d009de01b5f285b023c73ae643bfaaa0435e5af
- https://git.alpinelinux.org/aports/commit/?id=48505d9504858193f17f61dde0799de9dfff7c6c
- https://git.alpinelinux.org/aports/commit/?id=ddb14202fd187cde4f1bd4c5ffe322364b71eaa9
- https://git.alpinelinux.org/aports/commit/?id=856ed3ee75cfe016fe76d83c1929d05ea7e09763