|Main Archive Page > Month Archives > oss-security archives|
Hello Kurt, Josh, vendors,
Josh Bressers wrote:
> ----- Original Message -----
>> Unspecified vulnerability in the server component in Apache Subversion
>> 1.6.x before 1.6.15 allows remote attackers to cause a denial of
>> service via unknown vectors, related to a "several bug fixes,
>> including two which can cause client-initiated crashes on the server."
>>  http://svn.haxx.se/dev/archive-2010-11/0475.shtml
Cc-ed Hyrum to shed more light into this one.  mentions two issues:
several bug fixes, including two which can cause client-initiated
crashes on the server.
Further look at:
A, "* prevent crash in mod_dav_svn when using SVNParentPath (r1033166)" being the first one.
and after discussion with Joe Orton, Joe suggested:
B, * fix server-side memory leaks triggered by 'blame -g' (r1032808)
being the second one as denial of service attack (by memory consumption) against
Hyrum, could you confirm A, and B, issues are those two, mentioned in 
to be able to cause client-initiated crashes on the server?
> I admit, this isn't obvious, so let's use CVE-2010-4539 for now.
> We can split it if needed once more information is known.
Josh, since CVE-2010-4539 was assigned. Once Hyrum confirms, can
we consider CVE-2010-4539 to be a CVE identifier for A, issue
and request yet another / second one for B, issue?
Thanks && Regards, Jan.
-- Jan iankko Lieskovsky / Red Hat Security Response Team > > Thanks. >