summaryrefslogtreecommitdiffstats
path: root/scripts/lib/scriptutils.py
diff options
context:
space:
mode:
authorJiaying Song <jiaying.song.cn@windriver.com>2024-12-13 16:37:54 +0800
committerSteve Sakoman <steve@sakoman.com>2024-12-20 06:01:45 -0800
commitdffb6c2442556a16ef78133a445e81b033fe991a (patch)
tree550fad75860c750af65e6ce443070c2728c423b5 /scripts/lib/scriptutils.py
parent5ea79cac19c212dc2ac85216003cf6224a071f2f (diff)
downloadpoky-dffb6c2442556a16ef78133a445e81b033fe991a.tar.gz
subversion: fix CVE-2024-46901
Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository. All versions of Subversion up to and including Subversion 1.14.4 are affected if serving repositories via mod_dav_svn. Users are recommended to upgrade to version 1.14.5, which fixes this issue. Repositories served via other access methods are not affected. References: https://nvd.nist.gov/vuln/detail/CVE-2024-46901 Upstream patches: https://subversion.apache.org/security/CVE-2024-46901-advisory.txt (From OE-Core rev: 2082038de00090e4b10a151068876f83c83f94c7) Signed-off-by: Jiaying Song <jiaying.song.cn@windriver.com> Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'scripts/lib/scriptutils.py')
0 files changed, 0 insertions, 0 deletions