[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

RFS: subversion (updated package) [lenny-backports, 1.6.12dfsg-6~bpo50+1]



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Dear mentors and backporters,

I am looking for a sponsor for the new version 1.6.12dfsg-6~bpo50+1
of my package "subversion".

The new version addresses the following security issues:

CVE-2011-1752
  Subversion's mod_dav_svn Apache HTTPD server module will dereference
  a NULL pointer if asked to deliver baselined WebDAV resources.

CVE-2011-1783
  Subversion's mod_dav_svn Apache HTTPD server module may in certain
  scenarios enter a logic loop which does not exit and which allocates
  memory in each iteration, ultimately exhausting all the available
  memory on the server.

CVE-2011-1921
  Subversion's mod_dav_svn Apache HTTPD server module may leak to
  remote users the file contents of files configured to be unreadable
  by those users.

It builds these binary packages:
libapache2-svn - Subversion server modules for Apache
libsvn-dev - Development files for Subversion libraries
libsvn-doc - Developer documentation for libsvn
libsvn-java - Java bindings for Subversion
libsvn-perl - Perl bindings for Subversion
libsvn-ruby - Ruby bindings for Subversion (dummy package)
libsvn-ruby1.8 - Ruby bindings for Subversion
libsvn1    - Shared libraries used by Subversion
python-subversion - Python bindings for Subversion
subversion - Advanced version control system
subversion-tools - Assorted tools related to Subversion

The package can be found on mentors.debian.net:
- - URL: http://mentors.debian.net/debian/pool/main/s/subversion
- - Source repository: deb-src http://mentors.debian.net/debian unstable
main contrib non-free
- - dget
http://mentors.debian.net/debian/pool/main/s/subversion/subversion_1.6.12dfsg-6~bpo50+1.dsc

I would be glad if someone uploaded this package for me.

Kind regards
 Michael Diers

- -- 
Michael Diers, elego Software Solutions GmbH, http://www.elego.de

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (Cygwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk3mmawACgkQcEKlWnqVgz1yJACfelo+bmwaRdgNRVd/FZn77W8o
c/YAnRHJm5dD9HwKZsTMiNgdVGFIhSqk
=UMoE
-----END PGP SIGNATURE-----


Reply to: