diff options
author | Jiaying Song <jiaying.song.cn@windriver.com> | 2024-12-13 15:20:37 +0800 |
---|---|---|
committer | Steve Sakoman <steve@sakoman.com> | 2024-12-23 05:46:32 -0800 |
commit | 8f8989071a41ea73e9c2977445f45d541b7a198f (patch) | |
tree | 765ab3822d35c9ad665208d038a00a81350933f4 /documentation/conf.py | |
parent | 1e47fd8e4427f9d84048139804f75b83471bab28 (diff) | |
download | poky-8f8989071a41ea73e9c2977445f45d541b7a198f.tar.gz |
subversion: fix CVE-2024-46901
Insufficient validation of filenames against control characters in
Apache Subversion repositories served via mod_dav_svn allows
authenticated users with commit access to commit a corrupted revision,
leading to disruption for users of the repository. All versions of
Subversion up to and including Subversion 1.14.4 are affected if serving
repositories via mod_dav_svn. Users are recommended to upgrade to
version 1.14.5, which fixes this issue. Repositories served via other
access methods are not affected.
References:
https://nvd.nist.gov/vuln/detail/CVE-2024-46901
Upstream patches:
https://subversion.apache.org/security/CVE-2024-46901-advisory.txt
(From OE-Core rev: 16c212bd9a9e9c35256ff308da72a518c76ce11d)
Signed-off-by: Jiaying Song <jiaying.song.cn@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'documentation/conf.py')
0 files changed, 0 insertions, 0 deletions