[arch-dev-public] [signoff] subversion-1.6.17-1

Stéphane Gaudreault stephane at archlinux.org
Thu Jun 2 15:56:44 EDT 2011


Le 1 juin 2011 21:18:22, Stéphane Gaudreault a écrit :
> Hi,
> 
> I updated subversion to 1.6.17, which fix the following security issues [1]
> :
> 
>     CVE-2011-1752: Server NULL-pointer dereference
>     CVE-2011-1783: Server memory exhaustion
>     CVE-2011-1921: mod_dav_svn exposure of unreadable paths
> 
>     CVE-2011-0715 : a remotely-triggerable DoS for httpd-based Subversion
>                                   servers
> 
> This update also fix FS#24536.
> 
> Please test and signoff
> 
> Stéphane
> 
> [1] Changelogs :
>  - 1.6.17 : http://svn.haxx.se/dev/archive-2011-06/0030.shtml
>  - 1.6.16 : http://svn.haxx.se/dev/archive-2011-03/0122.shtml

There is a problem with perl 5.14 [1][2], but I got enough feedback to be 
confident that a -2 pkg compiled against perl 5.12.3 will not break everything.

I am going to push -2 in [extra] and -3 back in [testing] to debug perl stuff.

Stéphane

[1] https://bugs.archlinux.org/task/24540
[2] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=628507


More information about the arch-dev-public mailing list