Re: Subversion 1.8.14

Mark Phippard <[email protected]> Fri, 21 Aug 2015 08:48:47 -0400
Newsgroups gmane.comp.version-control.subversion.subclipse.user
Message-ID <CAHFaGCqswY2WciOMjZUuT19e+=m4Bs8k4eqAT+gi6q0VrNcdgw@mail.gmail.com>
------=_Part_18245_30469061.1440161333138
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

Yes there will be a new version when I have the javaHL binaries.

That said, those security fixes impact the server, not the client.  You
have to update your server for the fix. The version of the client has no
bearing on those issues.

I'll also add that this issue is mainly related to a very-specific Apache
configuration.  If you are not trying to mix anonymous access to your
repository then you are not vulnerable at all.

Mark



On Fri, Aug 21, 2015 at 2:30 AM, [email protected] <
[email protected]> wrote:

> Hello,
>
> will be there a new subclipse version with svn 1.8.14?
>
> CVE-2015-3184
> CVE-2015-3187
>
> Thanks for response
>
> ------------------------------------------------------
>
> http://subclipse.tigris.org/ds/viewMessage.do?dsForumId=1047&dsMessageId=3133217
>
> To unsubscribe from this discussion, e-mail: [
> [email protected]].
>



-- 
Thanks

Mark Phippard
http://markphip.blogspot.com/

------------------------------------------------------
http://subclipse.tigris.org/ds/viewMessage.do?dsForumId=1047&dsMessageId=3133263

To unsubscribe from this discussion, e-mail: [[email protected]].
------=_Part_18245_30469061.1440161333138
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Yes there will be a new version when I have the javaHL bin=
aries.<div><br></div><div>That said, those security fixes impact the server=
, not the client.=C2=A0 You have to update your server for the fix. The ver=
sion of the client has no bearing on those issues.</div><div><br></div><div=
>I&#39;ll also add that this issue is mainly related to a very-specific Apa=
che configuration.=C2=A0 If you are not trying to mix anonymous access to y=
our repository then you are not vulnerable at all.</div><div><br></div><div=
>Mark</div><div><br></div><div><br></div></div><div class=3D"gmail_extra"><=
br><div class=3D"gmail_quote">On Fri, Aug 21, 2015 at 2:30 AM, <a href=3D"m=
ailto:[email protected]">[email protected]</a> <span dir=3D"ltr">=
&lt;<a href=3D"mailto:[email protected]" target=3D"_blank">w_sullivan@=
outlook.com</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" styl=
e=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hello,<=
br>
<br>
will be there a new subclipse version with svn 1.8.14?<br>
<br>
CVE-2015-3184<br>
CVE-2015-3187<br>
<br>
Thanks for response<br>
<br>
------------------------------------------------------<br>
<a href=3D"http://subclipse.tigris.org/ds/viewMessage.do?dsForumId=3D1047&a=
mp;dsMessageId=3D3133217" rel=3D"noreferrer" target=3D"_blank">http://subcl=
ipse.tigris.org/ds/viewMessage.do?dsForumId=3D1047&amp;dsMessageId=3D313321=
7</a><br>
<br>
To unsubscribe from this discussion, e-mail: [<a href=3D"mailto:users-unsub=
[email protected]">[email protected]</a>].<b=
r>
</blockquote></div><br><br clear=3D"all"><div><br></div>-- <br><div class=
=3D"gmail_signature">Thanks<br><br>Mark Phippard<br><a href=3D"http://markp=
hip.blogspot.com/" target=3D"_blank">http://markphip.blogspot.com/</a></div=
>
</div>

------=_Part_18245_30469061.1440161333138--