CVE-2010-3315
Publication date 4 October 2010
Last updated 24 July 2024
Ubuntu priority
authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.
Status
Package | Ubuntu Release | Status |
---|---|---|
subversion | ||
Notes
mdeslaur
looks like this was introduced here: http://svn.apache.org/viewvc?view=revision&revision=865065 code in dapper and hardy doesn't look affected karmic+ binary is in universe, so adding appropriate tag.
Patch details
Package | Patch details |
---|---|
subversion |
References
Related Ubuntu Security Notices (USN)
- USN-1053-1
- Subversion vulnerabilities
- 1 February 2011