Subversion 1.0.3 Security Update Released

The Subversion development team has released version 1.0.3. This is a security bugfix release and the team suggests all Subversion users upgrade: “Subversion versions up to and including 1.0.2 have a buffer overflow in the date parsing code. Both client and server are vulnerable. The server is vulnerable over both httpd/DAV and svnserve (that is, over http://, https://, svn://, svn+ssh:// and other tunneled svn+*:// methods). Additionally, clients with shared working copies, or permissions that allow files in the administrative area of the working copy to be written by other users, are potentially exploitable.”

10 Comments

  1. 2004-05-20 9:09 am
  2. 2004-05-20 1:51 pm
  3. 2004-05-20 5:38 pm
  4. 2004-05-20 5:45 pm
  5. 2004-05-20 6:27 pm
  6. 2004-05-20 7:32 pm
  7. 2004-05-20 10:32 pm
  8. 2004-05-20 10:33 pm
  9. 2004-05-22 3:34 pm
  10. 2004-05-22 3:36 pm