Security Advisories (4)
CVE-2016-2167 (2016-05-05)

The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm string that is a prefix of an expected repository realm string.

CVE-2016-2168 (2016-05-05)

The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a crafted header in a (1) MOVE or (2) COPY request, involving an authorization check.

CVE-2017-9800 (2017-08-11)

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://.

CVE-2014-3528 (2014-08-19)

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.

NAME

svn-clean - Wipes out unversioned files from Subversion working copy

SYNOPSIS

svn-clean [options] [directory or file ...]

DESCRIPTION

svn-clean will scan the given files and directories recursively and find unversioned files and directories (files and directories that are not present in the Subversion repository). After the scan is done, these files and directories will be deleted.

If no file or directory is given, svn-clean defaults to the current directory (".").

svn-clean uses the SVN Perl modules if they are available. This is much faster than parsing the output of the svn command-line client.

OPTIONS

-e, --exclude

A regular expression for filenames to be exluded. For example, the following command will skip files ending in ".zip":

svn-clean --exclude '\.zip$'

Multiple exclude patterns can be specified. If at least one matches, then the file is skipped. For example, the following command will skip files ending in ".jpg" or ".png":

svn-clean --exclude '\.jpg$' --exclude '\.png$'

The following command will skip the entire "build" subdirectory:

svn-clean --exclude '^build(/|$)'

-f, --force

Files to which you do not have delete access (if running under VMS) or write access (if running under another OS) will not be deleted unless you use this option.

-N, --non-recursive

Do not search recursively for unversioned files and directories. Unversioned directories will still be deleted along with all their contents.

-q, --quiet

Do not print progress info. In particular, do not print a message each time a file is examined, giving the name of the file, and indicating whether "rmdir" or "unlink" is used to remove it, or that it's skipped.

-p, --print

Do not delete anything. Instead, print the name of every file and directory that would have been deleted.

-?, -h, --help

Prints a brief help message and exits.

--man

Prints the manual page and exits.

AUTHOR

Simon Perreault <nomis80@nomis80.org>