FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

subversion -- multiple DoS

Affected packages
subversion < 1.6.15
subversion-freebsd < 1.6.15

Details

VuXML ID 71612099-1e93-11e0-a587-001b77d09812
Discovery 2011-01-02
Entry 2011-01-13

Entry for CVE-2010-4539 says:

The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.15, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger the walking of SVNParentPath collections.

Entry for CVE-2010-4644 says:

Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.

References

Bugtraq ID 45655
CVE Name CVE-2010-4539
CVE Name CVE-2010-4644