Bug 13322

Summary: [CVE 21] subversion 1.13.0 CVEs found
Product: [ROSA-based products] ROSA Fresh Reporter: Yury <y.tumanov>
Component: System (kernel, glibc, systemd, bash, PAM...)Assignee: ROSA Linux Bugs <bugs>
Status: VERIFIED FIXED QA Contact: ROSA Linux Bugs <bugs>
Severity: normal    
Priority: Normal CC: a.proklov, i.gaptrakhmanov, m.novosyolov, pastordidi, s.matveev, v.potapov, y.tumanov
Version: AllFlags: v.potapov: qa_verified+
y.tumanov: secteam_verified+
a.proklov: published+
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: CVE-2020-17525, CVE-2021-28544,
Whiteboard:
Platform: 2021.1 ROSA Vulnerability identifier:
RPM Package: ISO-related:
Bad POT generating: Upstream:

Description Yury 2023-05-03 18:03:11 MSK
Please patch CVEs for package subversion version 1.13.0
  
INFO (CVEs are): subversion 1.13.0
 cves found
CVE-2020-17525
Desc: Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7
Link: https://nvd.nist.gov/vuln/detail/CVE-2020-17525
Severity: HIGH
CVE-2021-28544
Desc: Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact that the node was copied. Only the 'copyfrom' path is revealed; not its contents. Both httpd and svnserve servers are vulnerable.
Link: https://nvd.nist.gov/vuln/detail/CVE-2021-28544
Severity: MEDIUM
Comment 1 Mikhail Novosyolov 2023-05-15 15:30:44 MSK
Думаю, достаточно его просто обновить до последней версии. Это штука типа git.
Comment 2 ilfat 2023-05-27 16:37:35 MSK
********** QA ADVISORY **********

CVEs closed by project update


Updated to 1.14.2
  disabled build with ruby due to swig 4 errors

https://abf.io/build_lists/4446308
https://abf.io/build_lists/4446294
https://abf.io/build_lists/4446295


Added new project py3c
as it is required by the new version of subversion

https://abf.io/build_lists/4445747
https://abf.io/build_lists/4445749
https://abf.io/build_lists/4446261
Comment 3 Dmitry Postnikov 2023-06-01 09:40:07 MSK
***************************
The update sent to testings
Comment 4 Vladimir Potapov 2023-06-06 10:26:33 MSK
subversion-1.14.2-1
https://abf.io/build_lists/4446308
https://abf.io/build_lists/4446294
https://abf.io/build_lists/4446295

py3c-1.4-1
https://abf.io/build_lists/4445747
https://abf.io/build_lists/4445749
https://abf.io/build_lists/4446261
********************** Advisory *************************
CVEs closed by project update
*********************************************************
QA Verified
Comment 5 Yury 2023-07-05 11:10:38 MSK
Secteam Approved