svnauthcheck contains a flaw that is triggered when certain Apache httpd permissions are revoked with the ?* = ? statement. This may allow a local attacker to more easily gain access to a users system.
Classification
Location:
Local Access Required
Attack Type:
Other
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Authentication Required
Solution
Upgrade to version 1.0.14 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.