Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact that the node was copied. Only the 'copyfrom' path is revealed; not its contents. Both httpd and svnserve servers are vulnerable.
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "libapache2-mod-svn" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "libapache2-mod-svn-dbgsym" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "libapache2-svn" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "libsvn-dev" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "libsvn-dev-dbgsym" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "libsvn-doc" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "libsvn-java" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "libsvn-java-dbgsym" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "libsvn-perl" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "libsvn-perl-dbgsym" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "libsvn-ruby1.8" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "libsvn1" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "libsvn1-dbgsym" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "python-subversion" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "python-subversion-dbg" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "ruby-svn" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "ruby-svn-dbgsym" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "subversion" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "subversion-dbg" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "subversion-dbgsym" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "subversion-tools" }, { "binary_version": "1.9.3-2ubuntu1.3+esm1", "binary_name": "subversion-tools-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.9.7-4ubuntu1", "binary_name": "libapache2-mod-svn" }, { "binary_version": "1.9.7-4ubuntu1", "binary_name": "libapache2-mod-svn-dbgsym" }, { "binary_version": "1.9.7-4ubuntu1", "binary_name": "libsvn-dev" }, { "binary_version": "1.9.7-4ubuntu1", "binary_name": "libsvn-doc" }, { "binary_version": "1.9.7-4ubuntu1", "binary_name": "libsvn-java" }, { "binary_version": "1.9.7-4ubuntu1", "binary_name": "libsvn-java-dbgsym" }, { "binary_version": "1.9.7-4ubuntu1", "binary_name": "libsvn-perl" }, { "binary_version": "1.9.7-4ubuntu1", "binary_name": "libsvn-perl-dbgsym" }, { "binary_version": "1.9.7-4ubuntu1", "binary_name": "libsvn1" }, { "binary_version": "1.9.7-4ubuntu1", "binary_name": "libsvn1-dbgsym" }, { "binary_version": "1.9.7-4ubuntu1", "binary_name": "python-subversion" }, { "binary_version": "1.9.7-4ubuntu1", "binary_name": "python-subversion-dbg" }, { "binary_version": "1.9.7-4ubuntu1", "binary_name": "ruby-svn" }, { "binary_version": "1.9.7-4ubuntu1", "binary_name": "ruby-svn-dbgsym" }, { "binary_version": "1.9.7-4ubuntu1", "binary_name": "subversion" }, { "binary_version": "1.9.7-4ubuntu1", "binary_name": "subversion-dbgsym" }, { "binary_version": "1.9.7-4ubuntu1", "binary_name": "subversion-tools" }, { "binary_version": "1.9.7-4ubuntu1", "binary_name": "subversion-tools-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.13.0-3ubuntu0.1", "binary_name": "libapache2-mod-svn" }, { "binary_version": "1.13.0-3ubuntu0.1", "binary_name": "libapache2-mod-svn-dbgsym" }, { "binary_version": "1.13.0-3ubuntu0.1", "binary_name": "libsvn-dev" }, { "binary_version": "1.13.0-3ubuntu0.1", "binary_name": "libsvn-doc" }, { "binary_version": "1.13.0-3ubuntu0.1", "binary_name": "libsvn-java" }, { "binary_version": "1.13.0-3ubuntu0.1", "binary_name": "libsvn-java-dbgsym" }, { "binary_version": "1.13.0-3ubuntu0.1", "binary_name": "libsvn-perl" }, { "binary_version": "1.13.0-3ubuntu0.1", "binary_name": "libsvn-perl-dbgsym" }, { "binary_version": "1.13.0-3ubuntu0.1", "binary_name": "libsvn1" }, { "binary_version": "1.13.0-3ubuntu0.1", "binary_name": "libsvn1-dbgsym" }, { "binary_version": "1.13.0-3ubuntu0.1", "binary_name": "python-subversion" }, { "binary_version": "1.13.0-3ubuntu0.1", "binary_name": "python-subversion-dbgsym" }, { "binary_version": "1.13.0-3ubuntu0.1", "binary_name": "ruby-svn" }, { "binary_version": "1.13.0-3ubuntu0.1", "binary_name": "ruby-svn-dbgsym" }, { "binary_version": "1.13.0-3ubuntu0.1", "binary_name": "subversion" }, { "binary_version": "1.13.0-3ubuntu0.1", "binary_name": "subversion-dbgsym" }, { "binary_version": "1.13.0-3ubuntu0.1", "binary_name": "subversion-tools" }, { "binary_version": "1.13.0-3ubuntu0.1", "binary_name": "subversion-tools-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.14.1-3ubuntu0.22.04.1", "binary_name": "libapache2-mod-svn" }, { "binary_version": "1.14.1-3ubuntu0.22.04.1", "binary_name": "libapache2-mod-svn-dbgsym" }, { "binary_version": "1.14.1-3ubuntu0.22.04.1", "binary_name": "libsvn-dev" }, { "binary_version": "1.14.1-3ubuntu0.22.04.1", "binary_name": "libsvn-doc" }, { "binary_version": "1.14.1-3ubuntu0.22.04.1", "binary_name": "libsvn-java" }, { "binary_version": "1.14.1-3ubuntu0.22.04.1", "binary_name": "libsvn-java-dbgsym" }, { "binary_version": "1.14.1-3ubuntu0.22.04.1", "binary_name": "libsvn-perl" }, { "binary_version": "1.14.1-3ubuntu0.22.04.1", "binary_name": "libsvn-perl-dbgsym" }, { "binary_version": "1.14.1-3ubuntu0.22.04.1", "binary_name": "libsvn1" }, { "binary_version": "1.14.1-3ubuntu0.22.04.1", "binary_name": "libsvn1-dbgsym" }, { "binary_version": "1.14.1-3ubuntu0.22.04.1", "binary_name": "python3-subversion" }, { "binary_version": "1.14.1-3ubuntu0.22.04.1", "binary_name": "python3-subversion-dbgsym" }, { "binary_version": "1.14.1-3ubuntu0.22.04.1", "binary_name": "ruby-svn" }, { "binary_version": "1.14.1-3ubuntu0.22.04.1", "binary_name": "ruby-svn-dbgsym" }, { "binary_version": "1.14.1-3ubuntu0.22.04.1", "binary_name": "subversion" }, { "binary_version": "1.14.1-3ubuntu0.22.04.1", "binary_name": "subversion-dbgsym" }, { "binary_version": "1.14.1-3ubuntu0.22.04.1", "binary_name": "subversion-tools" }, { "binary_version": "1.14.1-3ubuntu0.22.04.1", "binary_name": "subversion-tools-dbgsym" } ] }