A server-side memory leak in Subversion before v1.6.15 allowed remote attackers to cause a denial of service (memory consumption and daemon outage or crash) via Subversion client "blame" or "log" operations performed on certain repository files, when the -g option (request to display additional merge history for the file) was used. References: [1] http://svn.haxx.se/dev/archive-2010-11/0102.shtml [2] http://svn.apache.org/repos/asf/subversion/tags/1.6.15/CHANGES Upstream changeset: [3] http://svn.apache.org/viewvc?view=revision&revision=1032808 Public PoC: [4] http://svn.haxx.se/dev/archive-2010-11/0163.shtml
This issue did not affect the versions of the subversion package, as shipped with Red Hat Enterprise Linux 4 and 5, as they did not support -g / --use-merge-history options yet. This issue affects the version of the subversion package, as shipped with Red Hat Enterprise Linux 6. -- This issue affects the version of the subversion package, as shipped with Fedora release of 13. The subversion-1.6.15-1.fc14 package for Fedora-14, currently present in -testing repository already contains fix for this issue.
Created subversion tracking bugs for this issue Affects: fedora-13 [bug 667786]
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2011:0257 https://rhn.redhat.com/errata/RHSA-2011-0257.html
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2011:0258 https://rhn.redhat.com/errata/RHSA-2011-0258.html