diff options
author | Jiaying Song <jiaying.song.cn@windriver.com> | 2024-12-13 16:37:54 +0800 |
---|---|---|
committer | Steve Sakoman <steve@sakoman.com> | 2024-12-20 06:01:45 -0800 |
commit | dffb6c2442556a16ef78133a445e81b033fe991a (patch) | |
tree | 550fad75860c750af65e6ce443070c2728c423b5 /scripts/lib/scriptutils.py | |
parent | 5ea79cac19c212dc2ac85216003cf6224a071f2f (diff) | |
download | poky-dffb6c2442556a16ef78133a445e81b033fe991a.tar.gz |
subversion: fix CVE-2024-46901
Insufficient validation of filenames against control characters in
Apache Subversion repositories served via mod_dav_svn allows
authenticated users with commit access to commit a corrupted revision,
leading to disruption for users of the repository. All versions of
Subversion up to and including Subversion 1.14.4 are affected if serving
repositories via mod_dav_svn. Users are recommended to upgrade to
version 1.14.5, which fixes this issue. Repositories served via other
access methods are not affected.
References:
https://nvd.nist.gov/vuln/detail/CVE-2024-46901
Upstream patches:
https://subversion.apache.org/security/CVE-2024-46901-advisory.txt
(From OE-Core rev: 2082038de00090e4b10a151068876f83c83f94c7)
Signed-off-by: Jiaying Song <jiaying.song.cn@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'scripts/lib/scriptutils.py')
0 files changed, 0 insertions, 0 deletions