<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>21097</bug_id>
          
          <creation_ts>2009-08-17 17:46:08 +0400</creation_ts>
          <short_desc>CVE-2009-2411: subversion heap overflow</short_desc>
          <delta_ts>2009-08-20 14:24:23 +0400</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>subversion</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://subversion.tigris.org/security/CVE-2009-2411-advisory.txt</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>security</keywords>
          <priority>P3</priority>
          <bug_severity>blocker</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Dmitry V. Levin">ldv</reporter>
          <assigned_to name="Andrey Cherepanov">cas</assigned_to>
          <cc>cas</cc>
    
    <cc>ender</cc>
    
    <cc>shrek</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>96667</commentid>
    <comment_count>0</comment_count>
    <who name="Dmitry V. Levin">ldv</who>
    <bug_when>2009-08-17 17:46:08 +0400</bug_when>
    <thetext>Subversion performs insufficient input validation of svndiff streams.
Malicious servers could cause heap overflows in clients, and malicious
clients with commit access could cause heap overflows in servers,
possibly leading to arbitrary code execution in both cases.

Upstream released new version to fix the problem.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>96782</commentid>
    <comment_count>1</comment_count>
    <who name="Repository Robot">repository-robot</who>
    <bug_when>2009-08-19 04:25:48 +0400</bug_when>
    <thetext>subversion-1.6.4-alt1 -&gt; sisyphus:

* Tue Aug 18 2009 Dmitry V. Levin &lt;ldv@altlinux&gt; 1.6.4-alt1

- Updated to 1.6.4 (CVE-2009-2411; closes: #21097).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>96904</commentid>
    <comment_count>2</comment_count>
    <who name="Afanasov Dmitry">ender</who>
    <bug_when>2009-08-20 14:24:23 +0400</bug_when>
    <thetext>спасибо, меня резко в командировку выгнали, только до почты добрался.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>