Info/EL5: Subversion / Mod_dav_svn

Home » CentOS » Info/EL5: Subversion / Mod_dav_svn
CentOS No Comments

Just to point out that EL5 does not get this patch:

https://rhn.redhat.com/errata/RHSA-2015-0165.html

“A NULL pointer dereference flaw was found in the way the mod_dav_svn module
handled REPORT requests. A remote, unauthenticated attacker could use a
specially crafted REPORT request to crash mod_dav_svn. (CVE-2014-3580)”

https://bugzilla.redhat.com/show_bug.cgi?id74054#c17