FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The last vuln.xml file processed by FreshPorts is:

Revision:  362844
Date:      2014-07-24
Time:      20:12:51Z
Committer: ohauer

List all Vulnerabilities, by package

List all Vulnerabilities, by date

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
b6beb137-9dc0-11e2-882f-20cf30e32f6dSubversion -- multiple vulnerabilities

Subversion team reports:

Subversion's mod_dav_svn Apache HTTPD server module will use excessive amounts of memory when a large number of properties are set or deleted on a node.

Subversion's mod_dav_svn Apache HTTPD server module will crash when a LOCK request is made against activity URLs.

Subversion's mod_dav_svn Apache HTTPD server module will crash in some circumstances when a LOCK request is made against a non-existent URL.

Subversion's mod_dav_svn Apache HTTPD server module will crash when a PROPFIND request is made against activity URLs.

Subversion's mod_dav_svn Apache HTTPD server module will crash when a log REPORT request receives a limit that is out of the allowed range.


Discovery 2013-04-05
Entry 2013-04-05
subversion
ge 1.7.0 lt 1.7.9

ge 1.6.0 lt 1.6.21

CVE-2013-1845
CVE-2013-1846
CVE-2013-1847
CVE-2013-1849
CVE-2013-1884
787d21b9-ca38-11e2-9673-001e8c75030ddevel/subversion -- fsfs repositories can be corrupted by newline characters in filenames

Subversion team reports:

If a filename which contains a newline character (ASCII 0x0a) is committed to a repository using the FSFS format, the resulting revision is corrupt.


Discovery 2013-05-31
Entry 2013-05-31
subversion
ge 1.7.0 lt 1.7.10

ge 1.1.0 lt 1.6.23

CVE-2013-1968
6d0bf320-ca39-11e2-9673-001e8c75030ddevel/subversion -- contrib hook-scripts can allow arbitrary code execution

Subversion team reports:

The script contrib/hook-scripts/check-mime-type.pl does not escape argv arguments to 'svnlook' that start with a hyphen. This could be used to cause 'svnlook', and hence check-mime-type.pl, to error out.

The script contrib/hook-scripts/svn-keyword-check.pl parses filenames from the output of 'svnlook changed' and passes them to a further shell command (equivalent to the 'system()' call of the C standard library) without escaping them. This could be used to run arbitrary shell commands in the context of the user whom the pre-commit script runs as (the user who owns the repository).


Discovery 2013-05-31
Entry 2013-05-31
subversion
ge 1.7.0 lt 1.7.10

ge 1.2.0 lt 1.6.23

CVE-2013-2088
ce502902-ca39-11e2-9673-001e8c75030ddevel/subversion -- svnserve remotely triggerable DoS

Subversion team reports:

Subversion's svnserve server process may exit when an incoming TCP connection is closed early in the connection process.


Discovery 2013-05-31
Entry 2013-05-31
subversion
ge 1.7.0 lt 1.7.10

ge 1.0.0 lt 1.6.23

CVE-2013-2112