Jump to content

Advisories MDVSA-2009:199-1: subversion


paul
 Share

Recommended Posts

A vulnerability has been found and corrected in subversion:

 

Multiple integer overflows in the libsvn_delta library in Subversion

before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users

and remote Subversion servers to execute arbitrary code via an svndiff

stream with large windows that trigger a heap-based buffer overflow,

a related issue to CVE-2009-2412 (CVE-2009-2411).

 

This update provides a solution to this vulnerability and in turn

upgrades subversion where possible to provide additional features

and upstream bugfixes and adds required dependencies where needed.

 

Update:

 

Packages for 2008.0 are being provided due to extended support for

Corporate products.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...