Re: Subversion 1.8.14
Mark Phippard <[email protected]> Fri, 21 Aug 2015 08:48:47 -0400
| Newsgroups | gmane.comp.version-control.subversion.subclipse.user |
|---|---|
| Message-ID | <CAHFaGCqswY2WciOMjZUuT19e+=m4Bs8k4eqAT+gi6q0VrNcdgw@mail.gmail.com> |
------=_Part_18245_30469061.1440161333138 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Yes there will be a new version when I have the javaHL binaries. That said, those security fixes impact the server, not the client. You have to update your server for the fix. The version of the client has no bearing on those issues. I'll also add that this issue is mainly related to a very-specific Apache configuration. If you are not trying to mix anonymous access to your repository then you are not vulnerable at all. Mark On Fri, Aug 21, 2015 at 2:30 AM, [email protected] < [email protected]> wrote: > Hello, > > will be there a new subclipse version with svn 1.8.14? > > CVE-2015-3184 > CVE-2015-3187 > > Thanks for response > > ------------------------------------------------------ > > http://subclipse.tigris.org/ds/viewMessage.do?dsForumId=1047&dsMessageId=3133217 > > To unsubscribe from this discussion, e-mail: [ > [email protected]]. > -- Thanks Mark Phippard http://markphip.blogspot.com/ ------------------------------------------------------ http://subclipse.tigris.org/ds/viewMessage.do?dsForumId=1047&dsMessageId=3133263 To unsubscribe from this discussion, e-mail: [[email protected]]. ------=_Part_18245_30469061.1440161333138 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Yes there will be a new version when I have the javaHL bin= aries.<div><br></div><div>That said, those security fixes impact the server= , not the client.=C2=A0 You have to update your server for the fix. The ver= sion of the client has no bearing on those issues.</div><div><br></div><div= >I'll also add that this issue is mainly related to a very-specific Apa= che configuration.=C2=A0 If you are not trying to mix anonymous access to y= our repository then you are not vulnerable at all.</div><div><br></div><div= >Mark</div><div><br></div><div><br></div></div><div class=3D"gmail_extra"><= br><div class=3D"gmail_quote">On Fri, Aug 21, 2015 at 2:30 AM, <a href=3D"m= ailto:[email protected]">[email protected]</a> <span dir=3D"ltr">= <<a href=3D"mailto:[email protected]" target=3D"_blank">w_sullivan@= outlook.com</a>></span> wrote:<br><blockquote class=3D"gmail_quote" styl= e=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hello,<= br> <br> will be there a new subclipse version with svn 1.8.14?<br> <br> CVE-2015-3184<br> CVE-2015-3187<br> <br> Thanks for response<br> <br> ------------------------------------------------------<br> <a href=3D"http://subclipse.tigris.org/ds/viewMessage.do?dsForumId=3D1047&a= mp;dsMessageId=3D3133217" rel=3D"noreferrer" target=3D"_blank">http://subcl= ipse.tigris.org/ds/viewMessage.do?dsForumId=3D1047&dsMessageId=3D313321= 7</a><br> <br> To unsubscribe from this discussion, e-mail: [<a href=3D"mailto:users-unsub= [email protected]">[email protected]</a>].<b= r> </blockquote></div><br><br clear=3D"all"><div><br></div>-- <br><div class= =3D"gmail_signature">Thanks<br><br>Mark Phippard<br><a href=3D"http://markp= hip.blogspot.com/" target=3D"_blank">http://markphip.blogspot.com/</a></div= > </div> ------=_Part_18245_30469061.1440161333138--