libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories and cause a denial of service or obtain sensitive information by editing packed revision properties.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://subversion.apache.org/security/CVE-2013-4246-advisory.txt | issue tracking patch vendor advisory |
http://www.securityfocus.com/bid/101620 | vdb entry third party advisory |