#6354 closed enhancement (fixed)
subversion-1.8.13
Reported by: | Fernando de Oliveira | Owned by: | Fernando de Oliveira |
---|---|---|---|
Priority: | high | Milestone: | 7.8 |
Component: | BOOK | Version: | SVN |
Severity: | normal | Keywords: | |
Cc: |
Description ¶
https://www.apache.org/dist/subversion/subversion-1.8.13.tar.bz2
SHA1: aa0bd14ac6a8f0fb178cc9ff325387de01cd7452 subversion-1.8.13.tar.bz2
This release addresses 3 security issues. CVE-2015-0202: Subversion HTTP servers with FSFS repositories are vulnerable to a remotely triggerable excessive memory use with certain REPORT requests. CVE-2015-0248: Subversion mod_dav_svn and svnserve are vulnerable to a remotely triggerable assertion DoS vulnerability for certain requests with dynamically evaluated revision numbers CVE-2015-0251: Subversion HTTP servers allow spoofing svn:author property values for new revisions For details see the advisories at: http://subversion.apache.org/security/CVE-2015-0202-advisory.txt http://subversion.apache.org/security/CVE-2015-0248-advisory.txt http://subversion.apache.org/security/CVE-2015-0251-advisory.txt
Change History (6)
comment:1 by , 10 years ago
Owner: | changed from | to
---|---|
Status: | new → assigned |
comment:2 by , 10 years ago
comment:5 by , 10 years ago
I got the same errors. I've tried to look at what they are trying to do, but don't understand ruby/java quite well enough to figure it out. They both have problems finding something they need.
We might want to reword what we have from "for unknown reasons" to "errors in the test suite".
comment:6 by , 10 years ago
I agree. Thank s for checking. Will you do, please, or do you want me to do it tomorrow?
Note:
See TracTickets
for help on using tickets.
Ruby and Java bindings checks completely fail. The others completely pass.
Ruby
Java: