[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: Subversion on SANS Top twenty list

From: Ben Reser <ben_at_reser.org>
Date: 2004-10-11 23:05:37 CEST

On Mon, Oct 11, 2004 at 10:16:04AM +0200, Lübbe_Onken wrote:
> has anybody read this:
> http://www.sans.org/top20/#u4
> a section about vulnerabilities in svnserve? And is this still true?

Blah. Remind me never to coordinate a release date on security stuff
with the CVS people again. Once again people are lumping our issue
together with the CVS issue simply because it was fixed/released on the
same day.

CVS belongs in the top 20. But we sure don't. As much as we'd like to
think Subversion has that type of market share, I just don't believe
that it's true.

So I can only conclude that we're included due to the timing and
publicity that the CVS issue got. If we'd released our fix a couple
days earlier or a couple days later, I bet we wouldn't even be on the

Ben Reser <ben@reser.org>
"Conscience is the inner voice which warns us somebody may be looking."
- H.L. Mencken
To unsubscribe, e-mail: dev-unsubscribe@subversion.tigris.org
For additional commands, e-mail: dev-help@subversion.tigris.org
Received on Mon Oct 11 23:06:51 2004

This is an archived mail posted to the Subversion Dev mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.