1.0.5 being cut within the next hour or so.
From: Ben Reser <ben_at_reser.org>
Date: 2004-06-10 19:52:52 CEST
Due to a security issue 1.0.5 if being released today.
Details below:
Subversion versions up to and including 1.0.4 have a potential
This affects only sites running svnserve. It does not affect
Details:
The svn protocol sends strings as a length followed by the string. The
The parsing code with the flaw is shared by both the svnserve server and
Severity:
Severity ranges from "Denial of Service" to, potentially, "Arbitrary
Since the error is in the parsing of the protocol, including the parsing
The Denial of Service attack is reasonably easy to carry out, while
Workarounds:
Disable svnserve and use DAV (http://) instead.
Recommendations:
We recommend all users upgrade to 1.0.5.
References:
CAN-2004-0413: Subversion svn:// protocol string parsing error.
-- Ben Reser <ben@reser.org> http://ben.reser.org "Conscience is the inner voice which warns us somebody may be looking." - H.L. Mencken --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscribe@subversion.tigris.org For additional commands, e-mail: dev-help@subversion.tigris.orgReceived on Thu Jun 10 19:53:36 2004 |
This is an archived mail posted to the Subversion Dev mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.