[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: Subversion 1.6.4 Released

From: Stefan Sperling <stsp_at_elego.de>
Date: Thu, 6 Aug 2009 22:59:42 +0100

On Thu, Aug 06, 2009 at 03:00:05PM -0500, Hyrum K. Wright wrote:
> Subversion 1.6.4 has been released, available from:
>
> http://subversion.tigris.org/downloads/subversion-1.6.4.tar.bz2
> http://subversion.tigris.org/downloads/subversion-1.6.4.tar.gz
> http://subversion.tigris.org/downloads/subversion-1.6.4.zip
> http://subversion.tigris.org/downloads/subversion-deps-1.6.4.tar.bz2
> http://subversion.tigris.org/downloads/subversion-deps-1.6.4.tar.gz
> http://subversion.tigris.org/downloads/subversion-deps-1.6.4.zip
>
> THIS IS A SECURITY RELEASE, addressing the issue described at:
>
> http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2411
>
> The CVE page may not be public yet when you read this, but will be soon.
> The full text of the advisory is available at:
>
> http://subversion.tigris.org/security/CVE-2009-2411-advisory.txt

Please note that due to human error an outdated version of the
advisory was published on the website shortly after this announcement.
This outdated version contained an incorrect patch and was present
on the site for about half an hour.

If you got the patch from the advisory shortly after the announcement,
please check the advisory again now to see if you really got the
correct patch.

Alternatively, get the release tarballs, which have always contained
the correct patch.

Stefan

------------------------------------------------------
http://subversion.tigris.org/ds/viewMessage.do?dsForumId=462&dsMessageId=2381100
Received on 2009-08-07 00:01:29 CEST

This is an archived mail posted to the Subversion Dev mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.