Overview

Request 176383 accepted

- update to 1.6.21 [bnc#813913], addressing remotely triggerable
vulnerabilities in mod_dav_svn which may result in denial of service:
+ CVE-2013-1845: mod_dav_svn excessive memory usage from property changes
+ CVE-2013-1846: mod_dav_svn crashes on LOCK requests against activity URLs
+ CVE-2013-1847: mod_dav_svn crashes on LOCK requests against non-existant URLs
+ CVE-2013-1849: mod_dav_svn crashes on PROPFIND requests against activity URLs
- further changes:
+ mod_dav_svn will omit some property values for activity urls
+ improve memory usage when committing properties in mod_dav_svn
+ fix mod_dav_svn runs pre-revprop-change twice
+ fixed: post-revprop-change errors cancel commit
+ improved logic in mod_dav_svn's implementation of lock.
+ fix a compatibility issue with g++ 4.7

- update to 1.6.20 (bnc#796050)
- Client- and server-side bugfixes:
* Fix typos in pt_BR, es and zh_TW translations
- Server-side bugfixes:
* add Vary: header to GET responses to improve cacheability
* fix fs_fs to cleanup after failed rep transmission
* fix an assert with SVNAutoVersioning in mod_dav_svn

- update to 1.6.19 (bnc#780848)
- Client-side bugfixes:
* handle missing svn:date reported by svnserve gracefully
- Server-side bugfixes:
* fix possible server hang if a hook script fails to start
* fix write-through proxy commit regression introduced in 1.6.17
* partial sync drops properties when converting to adds
- Developer-visible changes:

Loading...
Request History
Stefan Lijewski's avatar

lijews created request

- update to 1.6.21 [bnc#813913], addressing remotely triggerable
vulnerabilities in mod_dav_svn which may result in denial of service:
+ CVE-2013-1845: mod_dav_svn excessive memory usage from property changes
+ CVE-2013-1846: mod_dav_svn crashes on LOCK requests against activity URLs
+ CVE-2013-1847: mod_dav_svn crashes on LOCK requests against non-existant URLs
+ CVE-2013-1849: mod_dav_svn crashes on PROPFIND requests against activity URLs
- further changes:
+ mod_dav_svn will omit some property values for activity urls
+ improve memory usage when committing properties in mod_dav_svn
+ fix mod_dav_svn runs pre-revprop-change twice
+ fixed: post-revprop-change errors cancel commit
+ improved logic in mod_dav_svn's implementation of lock.
+ fix a compatibility issue with g++ 4.7

- update to 1.6.20 (bnc#796050)
- Client- and server-side bugfixes:
* Fix typos in pt_BR, es and zh_TW translations
- Server-side bugfixes:
* add Vary: header to GET responses to improve cacheability
* fix fs_fs to cleanup after failed rep transmission
* fix an assert with SVNAutoVersioning in mod_dav_svn

- update to 1.6.19 (bnc#780848)
- Client-side bugfixes:
* handle missing svn:date reported by svnserve gracefully
- Server-side bugfixes:
* fix possible server hang if a hook script fails to start
* fix write-through proxy commit regression introduced in 1.6.17
* partial sync drops properties when converting to adds
- Developer-visible changes:


Stefan Lijewski's avatar

lijews accepted request

openSUSE Build Service is sponsored by