VDB

MAGEIA-2014-339

MAGEIA-2014-339 PUBLISHED

Updated subversion packages fix security vulnerabilities: Ben Reser discovered that Subversion did not correctly validate SSL certificates containing wildcards. A remote attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications (CVE-2014-3522). Bert Huijben discovered that Subversion did not properly handle cached credentials. A malicious server could possibly use this issue to obtain credentials cached for a different server (CVE-2014-3528). The subversion package has been updated to 1.8.10 to fix these issues and other bugs.

Affected Products

VendorProductVersions
Mageiasubversion0, 1.8.10-1.mga4

Timeline

  • Aug 21, 2014 CVE Updated
  • Aug 21, 2014 CVE Published
  • Mar 17, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›