Debian Security Advisory

DLA-293-1 subversion -- LTS security update

Date Reported:
16 Aug 2015
Affected Packages:
subversion
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2015-3187.
More information:

C. Michael Pilato, from CollabNet, reported an issue in the version control system Subversion.

  • CVE-2015-3187

    Subversion servers revealed some sensible paths hidden by path-based authorization. Remote authenticated users were allowed to obtain path information by reading the history of a node that has been moved from a hidden path. The vulnerability only revealed the path, though it didn't reveal its content.

For Debian 6 Squeeze, this issue has been fixed in subversion 1.6.12dfsg-7+deb6u3. We recommend to upgrade your subversion packages.