-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 12 Aug 2014 21:57:23 -0400 Source: subversion Binary: subversion subversion-dbg libsvn1 libsvn-dev libsvn-doc libapache2-mod-svn libapache2-svn python-subversion subversion-tools libsvn-java libsvn-perl ruby-svn libsvn-ruby1.8 Architecture: source all amd64 Version: 1.8.10-1 Distribution: unstable Urgency: medium Maintainer: James McCoy <jamessan@debian.org> Changed-By: James McCoy <jamessan@debian.org> Description: libapache2-mod-svn - Apache Subversion server modules for Apache httpd libapache2-svn - Apache Subversion server modules for Apache httpd (dummy package) libsvn-dev - Development files for Apache Subversion libraries libsvn-doc - Developer documentation for libsvn libsvn-java - Java bindings for Apache Subversion libsvn-perl - Perl bindings for Apache Subversion libsvn-ruby1.8 - Ruby bindings for Apache Subversion (dummy package) libsvn1 - Shared libraries used by Apache Subversion python-subversion - Python bindings for Apache Subversion ruby-svn - Ruby bindings for Apache Subversion subversion - Advanced version control system subversion-dbg - Debug symbols for Apache Subversion subversion-tools - Assorted tools related to Apache Subversion Changes: subversion (1.8.10-1) unstable; urgency=medium . * New upstream release. Refresh patches. - Includes security fixes: + CVE-2014-3522: ra_serf improper validation of wildcards in SSL certs. + CVE-2014-3528: credentials cached with svn may be sent to wrong server. * debian/rules: Avoid an unnecessary call to dpkg-buildflags. * debian/control: Pre-Depend on ${misc:Pre-Depends} instead of hard-coding multiarch-support, as suggested by Lintian. Checksums-Sha1: f43145de617e826d54d92be12d5ed06088622b42 3108 subversion_1.8.10-1.dsc 8e1e1e5fd97c3f575a81d66232c62dc902257a17 9331079 subversion_1.8.10.orig.tar.gz cd113d2695bdd71216328f9acec80bc51cd97760 268227 subversion_1.8.10-1.diff.gz 1f68e03440838141f3a06bd31ec89d2c34df9f35 1406412 libsvn-doc_1.8.10-1_all.deb 93405f40ce32b5883d4c3bcda03fc427a24e5de8 124374 libapache2-svn_1.8.10-1_all.deb 0e3cbc6b6b2fe6848e4c3b1aa842f8051f8e7e7f 274284 subversion-tools_1.8.10-1_all.deb 5008f125278ebab0ab9687e162cbd01febcd1a21 1030 libsvn-ruby1.8_1.8.10-1_all.deb Checksums-Sha256: 082ef9baa320944992df8b80736f91533d9517c9308a06ce1dc72f03b7c59dd9 3108 subversion_1.8.10-1.dsc d0efa2533225c0bfba2ac27bcc004255997cbbde58f4f970dfb9dc3cc825005f 9331079 subversion_1.8.10.orig.tar.gz 8e6508230a040f00fc66486ed62336a279e14535a7229fdfbce0edca043986da 268227 subversion_1.8.10-1.diff.gz 036277616767b6bfcdbaf5e6366ea9a753d26b30a5aac1a2c0913d4cc8ded134 1406412 libsvn-doc_1.8.10-1_all.deb 92cf094b6547843ee1f097f5a41b904b914d9b04462098b19871143e45068691 124374 libapache2-svn_1.8.10-1_all.deb 99670e896186c8283a74af18063879310511c09e3b31a279a271fcca57ca116e 274284 subversion-tools_1.8.10-1_all.deb 0bf32a6d92730912770aa25c1e56608e34a29474dc92b121e4d6a5a36285025a 1030 libsvn-ruby1.8_1.8.10-1_all.deb Files: 0947878cfb2595a8585b2ef46cd121a0 1406412 doc extra libsvn-doc_1.8.10-1_all.deb 1be27f37156933ce4430224bb4a64663 124374 oldlibs extra libapache2-svn_1.8.10-1_all.deb 58cb1c25ada55594e1f3f58bfb50d941 274284 vcs extra subversion-tools_1.8.10-1_all.deb c4518523ebc7953a1e8766d8578be105 1030 oldlibs extra libsvn-ruby1.8_1.8.10-1_all.deb 9721402a737a8e6bb80e744c3b41851f 3108 vcs optional subversion_1.8.10-1.dsc 88cd7d8cc0fcdd00957ecca5c2550d5c 9331079 vcs optional subversion_1.8.10.orig.tar.gz 4f09e0150947dc6fc91c9cde18ecefb2 268227 vcs optional subversion_1.8.10-1.diff.gz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQJ8BAEBCgBmBQJT6tIyXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQ5MUJGQkY0RDY5NTZCRDVERjdCNzJEMjNE RkU2OTFBRTMzMUJBM0RCAAoJEN/mka4zG6Pbj48P/1jGuAHyihJo9v6irl64iK52 lDt59tQo7iJTJ/NQJZ+ZyVOMe0p/VDAklvUpNZ68Pa3HNt70LkttK1IGisvSC390 bQbIvp13WH410z+wZA+2hesTQRUWu0HXg4jJAqUilqmQDyMZkAiSBaeFpvXe2BwS PNcdAnPWxfl+wHiTp8fbyPKXpYr40hihNr3OlCuoXJvT4a1j/3DmGFcBBqEyb5h1 QdcLhalBkJpBH60gpikCrMlRGzOwCq3F17t29vuz3Rt4FJ/FYTdbW+NTpR5zo3Lm TqXdBEFN6M7ENgjdyRIBJbBTZqLYoGKgHO9xPTbfOnfvFp7nrJPRGfco0KgqdlFM 5bbGcAB4Qy7DiJglQqMpNCpsIDGpXtSrSvFkljTIh7AWtfzEu6YCT+aQHoHtAmk4 eLjv2Z2qynxwBNs5cMz9+Lm/FrBdyFU5yGGjjKQKnnkYi3fQzg4HJIGCf8P6SXnC 4Tq8q4qeIcCloJyaBLjh6cOa6rUFaGJKvBvmEeykRMgozaBNBq3+ru6jCEMTZBKv FoKm314MAe45O6u1AUDLxNWuSGv4ivrYRdBn4zUdiFWclGcJiZQ0T1ATWo0rfJm0 Uqd4A/2YbymLE9t6vxXRF1H1+wBidXJizFANE3bwe4SKECam7s7nd/xVqwyFUY/O IFlAnmdm522OSAdUliMc =tbSv -----END PGP SIGNATURE-----