Security Advisories (3)
CVE-2016-2167 (2016-05-05)

The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm string that is a prefix of an expected repository realm string.

CVE-2016-2168 (2016-05-05)

The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a crafted header in a (1) MOVE or (2) COPY request, involving an authorization check.

CVE-2017-9800 (2017-08-11)

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://.

NAME

Alien::SVN - A wrapper for installing the SVN Perl bindings

DESCRIPTION

Alien::SVN is a wrapper to install the Perl bindings for subversion, also known as SVN::Core. If your module needs SVN::Core it can depend on Alien::SVN instead and then the CPAN shell can handle automatic installation.

It comes with a copy of Subversion 1.4.5 which it will compile but only installs the Perl and Subversion libraries. The subversion binaries will not be installed.

LICENSE

Alien::SVN is copyright 2007 Michael G Schwern <schwern@pobox.com> and is licensed under the same terms as Perl itself. See http://www.perl.com/perl/misc/Artistic.html for licensing.

Subversion and SVN::Core are copyright (c) 2000-2006 CollabNet (http://www.colabnet.net). All rights reserved. See http://subversion.tigris.org/license-1.html for licensing.