CVE-2010-4644
Publication date 7 January 2011
Last updated 24 July 2024
Ubuntu priority
Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.
Status
Package | Ubuntu Release | Status |
---|---|---|
subversion | ||
Notes
mdeslaur
PoC: http://svn.haxx.se/dev/archive-2010-11/0163.shtml hardy and older don't support -g, 1.5.x and higher only
Patch details
Package | Patch details |
---|---|
subversion |
References
Related Ubuntu Security Notices (USN)
- USN-1053-1
- Subversion vulnerabilities
- 1 February 2011