[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

AW: AW: Logging Subversion client HTTP requests

From: Markus Schaber <m.schaber_at_3s-software.com>
Date: Mon, 1 Aug 2011 14:42:46 +0200

Hi, Andreas,

Von: Andreas Krey [mailto:a.krey_at_gmx.de]
>
> On Mon, 01 Aug 2011 08:57:52 +0000, Markus Schaber wrote:
> ...
> > Hmm. For http(s)://, svn:// and well set-up svn+ssh:// servers, he
> > should not be able to create repository corruption, right? I would
> > consider everything else to be a serious security bug in subversion.
>
> Setting invalid svn:mergeinfo counts as repository corruption? Then
it's
> possible.

But then that's something that you also can do via the standard svn
client libraries, so using a handcrafted client is not making things
worse here.

Best regards

Markus Schaber

___________________________
We software Automation.

3S-Smart Software Solutions GmbH
Markus Schaber | Developer
Memminger Str. 151 | 87439 Kempten | Germany | Tel. +49-831-54031-0 |
Fax +49-831-54031-50

Email: m.schaber@3s-software.com | Web: http://www.3s-software.com
CoDeSys internet forum: http://forum.3s-software.com
Download CoDeSys sample projects:
http://www.3s-software.com/index.shtml?sample_projects

Managing Directors: Dipl.Inf. Dieter Hess, Dipl.Inf. Manfred Werner |
Trade register: Kempten HRB 6186 | Tax ID No.: DE 167014915
Received on 2011-08-01 14:43:20 CEST

This is an archived mail posted to the Subversion Users mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.