Bug 1000192 (CVE-2013-4246) - CVE-2013-4246 subversion: FSFS repository corruption due to editing packed revision properties
Summary: CVE-2013-4246 subversion: FSFS repository corruption due to editing packed re...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2013-4246
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1000203
TreeView+ depends on / blocked
 
Reported: 2013-08-22 22:08 UTC by Vincent Danen
Modified: 2023-05-12 00:01 UTC (History)
1 user (show)

Fixed In Version: subversion 1.8.2
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-08-22 22:11:02 UTC
Embargoed:


Attachments (Terms of Use)
upstream patch to fix CVE-2013-4246 (2.56 KB, patch)
2013-08-22 22:10 UTC, Vincent Danen
no flags Details | Diff

Description Vincent Danen 2013-08-22 22:08:01 UTC
A flaw was reported in how the Subversion FSFS repository handled the packing of revision properties.  When one or more revision properties of a packed revision are set to new, larger values, a "pack file" in the repository might get split.  While this is happening, it is possible that the wrong pack file gets deleted, which can lead to data loss of revision property data.

This issue only affects FSFS repositories in Subversion 1.8.0 and 1.8.1.  It does not affect BDB repositories or earlier versions of Subversion.


Acknowledgements:

Red Hat would like to thank Ben Reser of the Apache Subversion project for reporting this issue. Upstream acknowledges Ivan Zhakov from VisualSVN as the original issue reporter.


Statement:

Not vulnerable.  This issue did not affect the versions of subversion as shipped with Red Hat Enterprise Linux 5 or 6, as they did not ship the vulnerable versions of subversion.

Comment 1 Vincent Danen 2013-08-22 22:09:47 UTC
This issue is embargoed until 29 August 2013 17:00 UTC.

Comment 2 Vincent Danen 2013-08-22 22:10:36 UTC
Created attachment 789383 [details]
upstream patch to fix CVE-2013-4246

Comment 3 Vincent Danen 2013-08-30 16:29:52 UTC
External References:

http://subversion.apache.org/security/CVE-2013-4246-advisory.txt


Note You need to log in before you can comment on or make changes to this bug.