[ubuntu/natty-security] subversion, subversion_1.6.12dfsg-4ubuntu2.1_powerpc_translations.tar.gz, subversion_1.6.12dfsg-4ubuntu2.1_amd64_translations.tar.gz, subversion_1.6.12dfsg-4ubuntu2.1_i386_translations.tar.gz, subversion_1.6.12dfsg-4ubuntu2.1_armel_translations.tar.gz 1.6.12dfsg-4ubuntu2.1 (Accepted)
Marc Deslauriers
marc.deslauriers at ubuntu.com
Mon Jun 6 14:03:42 UTC 2011
subversion (1.6.12dfsg-4ubuntu2.1) natty-security; urgency=low
* SECURITY UPDATE: denial of service via baselined WebDAV resource
request
- debian/patches/CVE-2011-1752.patch: disallow GETs of baselined
versions of resources in subversion/mod_dav_svn/repos.c.
- CVE-2011-1752
* SECURITY UPDATE: mod_dav_svn resource exhaustion via infinite loop
- debian/patches/CVE-2011-1783.patch: validate path in
subversion/libsvn_repos/authz.c.
- CVE-2011-1783
* SECURITY UPDATE: mod_dav_svn permissions bypass via incorrect
resource URL
- debian/patches/CVE-2011-1921.patch: validate path in
subversion/mod_dav_svn/authz.c.
- CVE-2011-1921
Date: Thu, 02 Jun 2011 13:15:00 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/natty/+source/subversion/1.6.12dfsg-4ubuntu2.1
-------------- next part --------------
Format: 1.8
Date: Thu, 02 Jun 2011 13:15:00 -0400
Source: subversion
Binary: subversion libsvn1 libsvn-dev libsvn-doc libapache2-svn python-subversion python-subversion-dbg subversion-tools libsvn-java libsvn-perl libsvn-ruby1.8 libsvn-ruby
Architecture: source
Version: 1.6.12dfsg-4ubuntu2.1
Distribution: natty-security
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description:
libapache2-svn - Subversion server modules for Apache
libsvn-dev - Development files for Subversion libraries
libsvn-doc - Developer documentation for libsvn
libsvn-java - Java bindings for Subversion
libsvn-perl - Perl bindings for Subversion
libsvn-ruby - Ruby bindings for Subversion (dummy package)
libsvn-ruby1.8 - Ruby bindings for Subversion
libsvn1 - Shared libraries used by Subversion
python-subversion - Python bindings for Subversion
python-subversion-dbg - Python bindings for Subversion (debug extension)
subversion - Advanced version control system
subversion-tools - Assorted tools related to Subversion
Changes:
subversion (1.6.12dfsg-4ubuntu2.1) natty-security; urgency=low
.
* SECURITY UPDATE: denial of service via baselined WebDAV resource
request
- debian/patches/CVE-2011-1752.patch: disallow GETs of baselined
versions of resources in subversion/mod_dav_svn/repos.c.
- CVE-2011-1752
* SECURITY UPDATE: mod_dav_svn resource exhaustion via infinite loop
- debian/patches/CVE-2011-1783.patch: validate path in
subversion/libsvn_repos/authz.c.
- CVE-2011-1783
* SECURITY UPDATE: mod_dav_svn permissions bypass via incorrect
resource URL
- debian/patches/CVE-2011-1921.patch: validate path in
subversion/mod_dav_svn/authz.c.
- CVE-2011-1921
Checksums-Sha1:
ebff7f917928942320755fcffa7f1fef04c3c1a3 2706 subversion_1.6.12dfsg-4ubuntu2.1.dsc
5c2b21c63d61194982f1ca279bb816716dbc3064 112128 subversion_1.6.12dfsg-4ubuntu2.1.diff.gz
Checksums-Sha256:
3a26dafd3d2ba03875d7f5e3844eef4c40ae2ea5402d0379c4feeda29897c3f2 2706 subversion_1.6.12dfsg-4ubuntu2.1.dsc
c6800679819604ff38bc5d97a848a97b7197071719d74e6d112af32ab2c3fda2 112128 subversion_1.6.12dfsg-4ubuntu2.1.diff.gz
Files:
2e1e3d54d70647a29ceefde3d1413123 2706 vcs optional subversion_1.6.12dfsg-4ubuntu2.1.dsc
8ce251ea0755ce8e1e7014cce1b023cf 112128 vcs optional subversion_1.6.12dfsg-4ubuntu2.1.diff.gz
Original-Maintainer: Peter Samuelson <peter at p12n.org>
More information about the Natty-changes
mailing list