USN-5322-1: Subversion vulnerability
10 March 2022
Subversion could be made to crash if it received specially crafted input.
Releases
Packages
- subversion - Advanced version control system
Details
Thomas Akesson discovered that Subversion incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
-
libapache2-svn
-
1.9.3-2ubuntu1.3+esm1
Available with Ubuntu Pro
-
libapache2-mod-svn
-
1.9.3-2ubuntu1.3+esm1
Available with Ubuntu Pro
-
subversion
-
1.9.3-2ubuntu1.3+esm1
Available with Ubuntu Pro
-
libsvn1
-
1.9.3-2ubuntu1.3+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References
Related notices
- USN-5445-1: libsvn1, ruby-svn, libsvn-dev, python-subversion, libsvn-doc, libapache2-mod-svn, subversion, subversion-tools, libsvn-java, libsvn-perl