CVE-2016-8734

Priority
Low
Description
Unrestricted XML entity expansion in mod_dontdothat and Subversion clients
using http(s)://
Ubuntu-Description
Florian Weimer discovered that Subversion clients did not properly
restrict XML entity expansion when accessing http(s):// URLs. A remote
attacker could use this to cause a denial of service.
References
Notes
 mdeslaur> for mod_dontdothat, we don't ship it in binary packages
 mdeslaur> for clients, we build with serf, so we're vulnerable
Package
Upstream:released (1.9.5-1, 1.8.17, 1.9.5)
Ubuntu 17.10 (Artful Aardvark):not-affected (1.9.5-1ubuntu1)
Ubuntu 12.04 ESM (Precise Pangolin):needed
Ubuntu 14.04 LTS (Trusty Tahr):released (1.8.8-1ubuntu3.3)
Ubuntu Core 15.04:DNE
Ubuntu 16.04 LTS (Xenial Xerus):released (1.9.3-2ubuntu1.1)
Ubuntu 17.04 (Zesty Zapus):not-affected (1.9.5-1ubuntu1)
Patches:
Upstream:https://subversion.apache.org/security/CVE-2016-8734-advisory.txt
More Information

Updated: 2017-08-11 23:23:23 UTC (commit 13081)