Posted on: 05/19/2004 02:54 PM

Updated subversion packages are available for Fedora Core 1

Fedora Update Notification

Product : Fedora Core 1
Name : subversion
Version : 0.32.1

Release : 2

Summary : A Concurrent Versioning system similar to, but better than, CVS.

Description :
Subversion is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes. Subversion only stores the differences between versions, instead of every complete file. Subversion is intended to be a compelling replacement for CVS.

Update Information:

Stefan Esser discovered an issue in the date parsing routines in Subversion which allows a buffer overflow. An attacker could send malicious requests to a Subversion server (either Apache-based using mod_dav_svn, or using the svnserve daemon) and perform arbitrary execution of code.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0397 to this issue. This update includes packages with a patch for this issue.

* Wed May 12 2004 Joe Orton jorton@redhat.com 0.32.1-2

- add security fix for CVE CAN-2004-0397 (Ben Reser)

This update can be downloaded from:

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.

