TortoiseSVN Spoofing Vulnerability

Posted on Saturday, July 03, 2010 @ 18:05:02 PDT in Security
by Raven

SECUNIA ADVISORY ID: SA40355

VERIFY ADVISORY: http://secunia.com/advisories/40355/

RELEASE DATE: 2010-07-01

DISCUSS ADVISORY: http://secunia.com/advisories/40355/#comments

DESCRIPTION: A vulnerability has been reported in TortoiseSVN, which can be exploited by malicious people to conduct spoofing attacks. The vulnerability is caused due to the use of a vulnerable version of the neon library.

For more information: SA36371. Note: This also fixes a Denial of Service when processing certain XML entities.


SOLUTION: Update to version 1.6.5.

PROVIDED AND/OR DISCOVERED BY: Reported by the vendor.

ORIGINAL ADVISORY: http://tortoisesvn.net/node/378

OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/products/corporate/EVM/
 
 
click Related        click Share
 
News ©

Site Info v2.2.2

Last SeenLast Seen
Server TrafficServer Traffic
  • Total: 362,151,668
  • Today: 50,852
Server InfoServer Info
  • Jul 21, 2018
  • 12:28 pm PDT
 
 

Daily Inspiration