Apple's CVE-2014-1266 and Subversion
From: Ben Reser <ben_at_reser.org>
Date: Sat, 22 Feb 2014 12:02:10 -0800
Background for people that haven't heard:
Subversion on OS X is **NOT** vulnerable to this.
First of all the problem is in Apple's SecureTransport functionality. Neither
For neon clients (1.7.x and older, though 1.4.x and newer can be using serf as
For serf clients (1.8.x or newer, 1.4.x optionally at configure time, 1.5.x and
You can check this by doing:
You should see an error about the SSL handshake or an error running context or
You can of course toggle between http library's with:
If you remove the port number and go to the default https port (which has a
|
This is an archived mail posted to the Subversion Dev mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.