ALAS2-2020-1549

Related Vulnerabilities: CVE-2018-11782  

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server. (CVE-2018-11782)

ALAS2-2020-1549


Amazon Linux 2 Security Advisory: ALAS-2020-1549
Advisory Release Date: 2020-10-22 18:43 Pacific
Advisory Updated Date: 2020-10-22 22:33 Pacific
Severity: Medium
References: CVE-2018-11782 

Issue Overview:

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server. (CVE-2018-11782)


Affected Packages:

subversion


Issue Correction:
Run yum update subversion to update your system.

New Packages:
aarch64:
    subversion-1.7.14-16.amzn2.0.1.aarch64
    subversion-libs-1.7.14-16.amzn2.0.1.aarch64
    subversion-python-1.7.14-16.amzn2.0.1.aarch64
    subversion-devel-1.7.14-16.amzn2.0.1.aarch64
    subversion-gnome-1.7.14-16.amzn2.0.1.aarch64
    mod_dav_svn-1.7.14-16.amzn2.0.1.aarch64
    subversion-perl-1.7.14-16.amzn2.0.1.aarch64
    subversion-javahl-1.7.14-16.amzn2.0.1.aarch64
    subversion-ruby-1.7.14-16.amzn2.0.1.aarch64
    subversion-tools-1.7.14-16.amzn2.0.1.aarch64
    subversion-debuginfo-1.7.14-16.amzn2.0.1.aarch64

i686:
    subversion-1.7.14-16.amzn2.0.1.i686
    subversion-libs-1.7.14-16.amzn2.0.1.i686
    subversion-python-1.7.14-16.amzn2.0.1.i686
    subversion-devel-1.7.14-16.amzn2.0.1.i686
    subversion-gnome-1.7.14-16.amzn2.0.1.i686
    mod_dav_svn-1.7.14-16.amzn2.0.1.i686
    subversion-perl-1.7.14-16.amzn2.0.1.i686
    subversion-javahl-1.7.14-16.amzn2.0.1.i686
    subversion-ruby-1.7.14-16.amzn2.0.1.i686
    subversion-tools-1.7.14-16.amzn2.0.1.i686
    subversion-debuginfo-1.7.14-16.amzn2.0.1.i686

src:
    subversion-1.7.14-16.amzn2.0.1.src

x86_64:
    subversion-1.7.14-16.amzn2.0.1.x86_64
    subversion-libs-1.7.14-16.amzn2.0.1.x86_64
    subversion-python-1.7.14-16.amzn2.0.1.x86_64
    subversion-devel-1.7.14-16.amzn2.0.1.x86_64
    subversion-gnome-1.7.14-16.amzn2.0.1.x86_64
    mod_dav_svn-1.7.14-16.amzn2.0.1.x86_64
    subversion-perl-1.7.14-16.amzn2.0.1.x86_64
    subversion-javahl-1.7.14-16.amzn2.0.1.x86_64
    subversion-ruby-1.7.14-16.amzn2.0.1.x86_64
    subversion-tools-1.7.14-16.amzn2.0.1.x86_64
    subversion-debuginfo-1.7.14-16.amzn2.0.1.x86_64