lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [day] [month] [year] [list]
Message-Id: <E1XOmlg-0001Lp-Sr@titan.mandriva.com>
Date: Tue, 02 Sep 2014 14:01:00 +0200
From: security@...driva.com
To: bugtraq@...urityfocus.com
Subject: [ MDVSA-2014:161 ] subversion

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 _______________________________________________________________________

 Mandriva Linux Security Advisory                         MDVSA-2014:161
 http://www.mandriva.com/en/support/security/
 _______________________________________________________________________

 Package : subversion
 Date    : September 2, 2014
 Affected: Business Server 1.0
 _______________________________________________________________________

 Problem Description:

 Updated subversion packages fix security vulnerability:
 
 Bert Huijben discovered that Subversion did not properly handle
 cached credentials. A malicious server could possibly use this issue
 to obtain credentials cached for a different server (CVE-2014-3528).
 _______________________________________________________________________

 References:

 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3528
 http://advisories.mageia.org/MGASA-2014-0338.html
 _______________________________________________________________________

 Updated Packages:

 Mandriva Business Server 1/X86_64:
 bff94b4e4e824974e46de8479ade18cb  mbs1/x86_64/apache-mod_dav_svn-1.7.18-1.mbs1.x86_64.rpm
 58326f310ce3494f20282afc19ed4061  mbs1/x86_64/lib64svn0-1.7.18-1.mbs1.x86_64.rpm
 fa40f52b246ae493e6440852ed70b32f  mbs1/x86_64/lib64svn-gnome-keyring0-1.7.18-1.mbs1.x86_64.rpm
 103acf16dd9692d7f4e14959ff8aff4e  mbs1/x86_64/lib64svnjavahl1-1.7.18-1.mbs1.x86_64.rpm
 f32ac961da41597fa3d4f24439baa9e3  mbs1/x86_64/perl-SVN-1.7.18-1.mbs1.x86_64.rpm
 1b2377acf97ac1ae29c1d32ec9ef646d  mbs1/x86_64/perl-svn-devel-1.7.18-1.mbs1.x86_64.rpm
 e3c458d6e08d88f842acee45f3b44cd6  mbs1/x86_64/python-svn-1.7.18-1.mbs1.x86_64.rpm
 0b513c377e565bcb5937e4eb0823987d  mbs1/x86_64/python-svn-devel-1.7.18-1.mbs1.x86_64.rpm
 e2c18cbc444edd590721ae25d8ad432e  mbs1/x86_64/ruby-svn-1.7.18-1.mbs1.x86_64.rpm
 ea8a558b8377632a392ce7255236171c  mbs1/x86_64/ruby-svn-devel-1.7.18-1.mbs1.x86_64.rpm
 c91b30c1e098755035c4e4c22feb8e40  mbs1/x86_64/subversion-1.7.18-1.mbs1.x86_64.rpm
 67cfade102c99c9d6132f79704e57c92  mbs1/x86_64/subversion-devel-1.7.18-1.mbs1.x86_64.rpm
 b2c398deadbfac328f4877b2d327fd34  mbs1/x86_64/subversion-doc-1.7.18-1.mbs1.x86_64.rpm
 2351edb7943867504f2b504f1c0229eb  mbs1/x86_64/subversion-gnome-keyring-devel-1.7.18-1.mbs1.x86_64.rpm
 49e98012f5fa91b2c80c9644101989e2  mbs1/x86_64/subversion-server-1.7.18-1.mbs1.x86_64.rpm
 baf8bcb91630989fd4184160f87feb40  mbs1/x86_64/subversion-tools-1.7.18-1.mbs1.x86_64.rpm
 e73e0d9050b45af13591670c97caa904  mbs1/x86_64/svn-javahl-1.7.18-1.mbs1.x86_64.rpm 
 93bb920b95f39679ba014da195bc6237  mbs1/SRPMS/subversion-1.7.18-1.mbs1.src.rpm
 _______________________________________________________________________

 To upgrade automatically use MandrivaUpdate or urpmi.  The verification
 of md5 checksums and GPG signatures is performed automatically for you.

 All packages are signed by Mandriva for security.  You can obtain the
 GPG public key of the Mandriva Security Team by executing:

  gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

 You can view other update advisories for Mandriva Linux at:

  http://www.mandriva.com/en/support/security/advisories/

 If you want to report vulnerabilities, please contact

  security_(at)_mandriva.com
 _______________________________________________________________________

 Type Bits/KeyID     Date       User ID
 pub  1024D/22458A98 2000-07-10 Mandriva Security Team
  <security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iD8DBQFUBaOGmqjQ0CJFipgRAk32AKDCwQsio9x3WrZnKNy1MOf5LDvJ3gCgtS3Q
ct3IdlMq1mqCiZSzQ2T4hcg=
=M9D+
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ