subversion
237
1.212. subversion
1.212.1. RHSA-2009:1203: Important security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:1203
1676
Updated subversion packages that fix multiple security issues are now available for Red Hat
Enterprise Linux 4 and 5.
This update has been rated as having important security impact by the Red Hat Security Response
Team.
Subversion (SVN) is a concurrent version control system which enables one or more users to
collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of
all changes.
Matt Lewis, of Google, reported multiple heap overflow flaws in Subversion (server and client) when
parsing binary deltas. A malicious user with commit access to a server could use these flaws to cause
a heap overflow on that server. A malicious server could use these flaws to cause a heap overflow
on a client when it attempts to checkout or update. These heap overflows can result in a crash or,
possibly, arbitrary code execution. (
CVE-2009-2411
1677
)
All Subversion users should upgrade to these updated packages, which contain a backported patch to
correct these issues. After installing the updated packages, the Subversion server must be restarted
for the update to take effect: restart httpd if you are using mod_dav_svn, or restart svnserve if it is
used.
1.213. sudo
1.213.1. RHSA-2009:0267: Moderate security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:0267
1678
An updated sudo package to fix a security issue is now available for Red Hat Enterprise Linux 5.
This update has been rated as having moderate security impact by the Red Hat Security Response
Team.
The sudo (superuser do) utility allows system administrators to give certain users the ability to run
commands as root with logging.
1677
https://www.redhat.com/security/data/cve/CVE-2009-2411.html
Summary of Contents for ENTERPRISE 5.4 RELEASE NOTES
Page 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Page 18: ...xviii ...
Page 306: ...288 ...
Page 464: ...446 ...
Page 466: ...448 ...