Rapid7 Vulnerability & Exploit Database

RHSA-2011:0258: subversion security update

Back to Search

RHSA-2011:0258: subversion security update



Subversion (SVN) is a concurrent version control system which enables oneor more users to collaborate in developing and maintaining a hierarchy offiles and directories while keeping a history of all changes. Themod_dav_svn module is used with the Apache HTTP Server to allow access toSubversion repositories via HTTP.An access restriction bypass flaw was found in the mod_dav_svn module. Ifthe SVNPathAuthz directive was set to "short_circuit", certain access ruleswere not enforced, possibly allowing sensitive repository data to be leakedto remote users. Note that SVNPathAuthz is set to "On" by default.(CVE-2010-3315)A server-side memory leak was found in the Subversion server. If amalicious, remote user performed "svn blame" or "svn log" operations oncertain repository files, it could cause the Subversion server to consumea large amount of system memory. (CVE-2010-4644)A NULL pointer dereference flaw was found in the way the mod_dav_svn moduleprocessed certain requests. If a malicious, remote user issued a certaintype of request to display a collection of Subversion repositories on ahost that has the SVNListParentPath directive enabled, it could cause thehttpd process serving the request to crash. Note that SVNListParentPath isnot enabled by default. (CVE-2010-4539)All Subversion users should upgrade to these updated packages, whichcontain backported patches to correct these issues. After installing theupdated packages, the Subversion server must be restarted for the updateto take effect: restart httpd if you are using mod_dav_svn, or restartsvnserve if it is used.


  • redhat-upgrade-mod_dav_svn
  • redhat-upgrade-subversion
  • redhat-upgrade-subversion-debuginfo
  • redhat-upgrade-subversion-devel
  • redhat-upgrade-subversion-gnome
  • redhat-upgrade-subversion-javahl
  • redhat-upgrade-subversion-kde
  • redhat-upgrade-subversion-perl
  • redhat-upgrade-subversion-ruby
  • redhat-upgrade-subversion-svn2cl

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center