Security Advisories (3)
CVE-2016-2167 (2016-05-05)

The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm string that is a prefix of an expected repository realm string.

CVE-2016-2168 (2016-05-05)

The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a crafted header in a (1) MOVE or (2) COPY request, involving an authorization check.

CVE-2017-9800 (2017-08-11)

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://.

NAME

Alien::SVN - A wrapper for installing the SVN Perl bindings

DESCRIPTION

Alien::SVN is a wrapper to install the Perl bindings for subversion, also known as SVN::Core. If your module needs SVN::Core it can depend on Alien::SVN instead and then the CPAN shell can handle automatic installation. This is particularly useful for programs like SVK.

It comes with a copy of Subversion 1.4.5 which it will compile but only installs the Perl and Subversion libraries. The subversion binaries will not be installed.

BUGS and FEEDBACK

Please send bug reports, problems and feedback to <bug-Alien-SVN> at <rt.cpan.org>. Or use the web interface at http://rt.cpan.org.

Report early, report often.

LICENSE

Alien::SVN is copyright 2007 Michael G Schwern <schwern@pobox.com> and is licensed under the same terms as Perl itself. See http://www.perl.com/perl/misc/Artistic.html for licensing.

Subversion and SVN::Core are copyright (c) 2000-2006 CollabNet http://www.colabnet.net. All rights reserved. See http://subversion.tigris.org/license-1.html for licensing.