[ubuntu/lucid-security] subversion_1.6.6dfsg-2ubuntu1.1_amd64_translations.tar.gz, subversion_1.6.6dfsg-2ubuntu1.1_powerpc_translations.tar.gz, subversion_1.6.6dfsg-2ubuntu1.1_ia64_translations.tar.gz, subversion_1.6.6dfsg-2ubuntu1.1_i386_translations.tar.gz, subversion, subversion_1.6.6dfsg-2ubuntu1.1_sparc_translations.tar.gz (delayed), subversion_1.6.6dfsg-2ubuntu1.1_armel_translations.tar.gz 1.6.6dfsg-2ubuntu1.1 (Accepted)
Ubuntu Installer
archive at ubuntu.com
Tue Feb 1 14:05:16 UTC 2011
subversion (1.6.6dfsg-2ubuntu1.1) lucid-security; urgency=low
* SECURITY UPDATE: restriction bypass via named repo as a rule scope
- debian/patches/CVE-2010-3315.patch: use repo_basename in
subversion/mod_dav_svn/authz.c.
- CVE-2010-3315
* SECURITY UPDATE: denial of service via SVNParentPath walking
- debian/patches/CVE-2010-4539.patch: don't try and walk SVNParentPath
collection in subversion/mod_dav_svn/repos.c.
- CVE-2010-4539
* SECURITY UPDATE: denial of service via -g memory leaks
- debian/patches/CVE-2010-4644.patch: improve logic in
subversion/libsvn_repos/rev_hunt.c.
- CVE-2010-4644
Date: Fri, 14 Jan 2011 12:36:43 -0600
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/lucid/+source/subversion/1.6.6dfsg-2ubuntu1.1
-------------- next part --------------
Format: 1.8
Date: Fri, 14 Jan 2011 12:36:43 -0600
Source: subversion
Binary: subversion libsvn1 libsvn-dev libsvn-doc libapache2-svn python-subversion python-subversion-dbg subversion-tools libsvn-java libsvn-perl libsvn-ruby1.8 libsvn-ruby
Architecture: source
Version: 1.6.6dfsg-2ubuntu1.1
Distribution: lucid-security
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description:
libapache2-svn - Subversion server modules for Apache
libsvn-dev - Development files for Subversion libraries
libsvn-doc - Developer documentation for libsvn
libsvn-java - Java bindings for Subversion
libsvn-perl - Perl bindings for Subversion
libsvn-ruby - Ruby bindings for Subversion (dummy package)
libsvn-ruby1.8 - Ruby bindings for Subversion
libsvn1 - Shared libraries used by Subversion
python-subversion - Python bindings for Subversion
python-subversion-dbg - Python bindings for Subversion (debug extension)
subversion - Advanced version control system
subversion-tools - Assorted tools related to Subversion
Changes:
subversion (1.6.6dfsg-2ubuntu1.1) lucid-security; urgency=low
.
* SECURITY UPDATE: restriction bypass via named repo as a rule scope
- debian/patches/CVE-2010-3315.patch: use repo_basename in
subversion/mod_dav_svn/authz.c.
- CVE-2010-3315
* SECURITY UPDATE: denial of service via SVNParentPath walking
- debian/patches/CVE-2010-4539.patch: don't try and walk SVNParentPath
collection in subversion/mod_dav_svn/repos.c.
- CVE-2010-4539
* SECURITY UPDATE: denial of service via -g memory leaks
- debian/patches/CVE-2010-4644.patch: improve logic in
subversion/libsvn_repos/rev_hunt.c.
- CVE-2010-4644
Checksums-Sha1:
09847812451846f1c4368d252a214c17efa0b78e 2683 subversion_1.6.6dfsg-2ubuntu1.1.dsc
c57ffc577b806603d5441782356a4e9d2d755d80 113229 subversion_1.6.6dfsg-2ubuntu1.1.diff.gz
Checksums-Sha256:
2ec05d4bebdc7e2c7c13c440157ad45424d33dbfddc7d014002c52f573b3b274 2683 subversion_1.6.6dfsg-2ubuntu1.1.dsc
5394174a2c2e8110f0a1db903e7c8398342a562a31239537b3f37f25f7d033dc 113229 subversion_1.6.6dfsg-2ubuntu1.1.diff.gz
Files:
fecd83d9cae9d8460eb81f8eeb81a6eb 2683 vcs optional subversion_1.6.6dfsg-2ubuntu1.1.dsc
91e4c53093dca55bc4fbf8ec98720e36 113229 vcs optional subversion_1.6.6dfsg-2ubuntu1.1.diff.gz
Original-Maintainer: Peter Samuelson <peter at p12n.org>
More information about the Lucid-changes
mailing list