Amazon Linux 2023 Security Advisory: ALAS-2023-011
Advisory Release Date: 2023-02-17 20:42 Pacific
Advisory Updated Date: 2023-02-23 00:00 Pacific
A flaw was found in Subversion. When using path-based authorization (authz), the helper function detect_changed() does not omit potentially sensitive information from log messages. In particular, if a node is copied from a protected location, its copyfrom path (the path to the protected location) is reported even when omission should occur. (CVE-2021-28544)
A use-after-free vulnerability was found in Subversion in the mod_dav_svn Apache HTTP server (HTTPd) module. While looking up path-based authorization (authz) rules, multiple calls to the post_config hook can invalidate cached pointers to object-pools, which Subversion subsequently uses. This issue crashes the single HTTPd worker thread or the entire HTTPd server process, depending on the configuration of the Apache HTTPd server. (CVE-2022-24070)
Affected Packages:
subversion
Issue Correction:
Run dnf update subversion --releasever=2023.0.20230222 to update your system.
aarch64:
subversion-devel-debuginfo-1.14.2-5.amzn2023.0.2.aarch64
subversion-1.14.2-5.amzn2023.0.2.aarch64
subversion-libs-debuginfo-1.14.2-5.amzn2023.0.2.aarch64
subversion-tools-debuginfo-1.14.2-5.amzn2023.0.2.aarch64
subversion-debuginfo-1.14.2-5.amzn2023.0.2.aarch64
subversion-perl-debuginfo-1.14.2-5.amzn2023.0.2.aarch64
python3-subversion-debuginfo-1.14.2-5.amzn2023.0.2.aarch64
subversion-devel-1.14.2-5.amzn2023.0.2.aarch64
subversion-debugsource-1.14.2-5.amzn2023.0.2.aarch64
subversion-libs-1.14.2-5.amzn2023.0.2.aarch64
subversion-perl-1.14.2-5.amzn2023.0.2.aarch64
subversion-tools-1.14.2-5.amzn2023.0.2.aarch64
python3-subversion-1.14.2-5.amzn2023.0.2.aarch64
noarch:
subversion-javahl-1.14.2-5.amzn2023.0.2.noarch
src:
subversion-1.14.2-5.amzn2023.0.2.src
x86_64:
subversion-perl-debuginfo-1.14.2-5.amzn2023.0.2.x86_64
subversion-libs-debuginfo-1.14.2-5.amzn2023.0.2.x86_64
subversion-tools-1.14.2-5.amzn2023.0.2.x86_64
subversion-tools-debuginfo-1.14.2-5.amzn2023.0.2.x86_64
python3-subversion-debuginfo-1.14.2-5.amzn2023.0.2.x86_64
subversion-devel-debuginfo-1.14.2-5.amzn2023.0.2.x86_64
subversion-1.14.2-5.amzn2023.0.2.x86_64
subversion-debugsource-1.14.2-5.amzn2023.0.2.x86_64
subversion-libs-1.14.2-5.amzn2023.0.2.x86_64
python3-subversion-1.14.2-5.amzn2023.0.2.x86_64
subversion-debuginfo-1.14.2-5.amzn2023.0.2.x86_64
subversion-perl-1.14.2-5.amzn2023.0.2.x86_64
subversion-devel-1.14.2-5.amzn2023.0.2.x86_64