]> code.ossystems Code Review - openembedded-core.git/commit
subversion: Security Advisory - subversion - CVE-2014-3522
authorYue Tao <Yue.Tao@windriver.com>
Wed, 22 Oct 2014 07:37:28 +0000 (03:37 -0400)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Tue, 4 Nov 2014 10:19:53 +0000 (10:19 +0000)
commit06a33cd00ea11abec1ebe9d5883e44778075ccc6
tree69ed9389a6011d7ea1251bbfc2d9c6e6f6b0e326
parentffc1c58809a2f5fef13484613d1b57c2d4c5ebfb
subversion: Security Advisory - subversion - CVE-2014-3522

The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18
and 1.8.x before 1.8.10 does not properly handle wildcards in the Common
Name (CN) or subjectAltName field of the X.509 certificate, which allows
man-in-the-middle attackers to spoof servers via a crafted
certificate.<a href=http://cwe.mitre.org/data/definitions/297.html
target=_blank>CWE-297: Improper Validation of Certificate with Host
Mismatch</a>

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3522

Signed-off-by: Yue Tao <Yue.Tao@windriver.com>
Signed-off-by: Jackie Huang <jackie.huang@windriver.com>
Signed-off-by: Ross Burton <ross.burton@intel.com>
meta/recipes-devtools/subversion/subversion-1.8.9/subversion-CVE-2014-3522.patch [new file with mode: 0644]
meta/recipes-devtools/subversion/subversion/subversion-CVE-2014-3522.patch [new file with mode: 0644]
meta/recipes-devtools/subversion/subversion_1.6.15.bb
meta/recipes-devtools/subversion/subversion_1.8.9.bb