-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 20 Apr 2015 22:19:47 -0400 Source: subversion Binary: subversion libsvn1 libsvn-dev libsvn-doc libapache2-svn python-subversion subversion-tools libsvn-java libsvn-perl libsvn-ruby1.8 libsvn-ruby Architecture: source all amd64 Version: 1.6.12dfsg-7+deb6u2 Distribution: squeeze-lts Urgency: high Maintainer: Peter Samuelson <peter@p12n.org> Changed-By: James McCoy <jamessan@debian.org> Description: libapache2-svn - Subversion server modules for Apache libsvn-dev - Development files for Subversion libraries libsvn-doc - Developer documentation for libsvn libsvn-java - Java bindings for Subversion libsvn-perl - Perl bindings for Subversion libsvn-ruby - Ruby bindings for Subversion (dummy package) libsvn-ruby1.8 - Ruby bindings for Subversion libsvn1 - Shared libraries used by Subversion python-subversion - Python bindings for Subversion subversion - Advanced version control system subversion-tools - Assorted tools related to Subversion Closes: 704940 737815 Changes: subversion (1.6.12dfsg-7+deb6u2) squeeze-lts; urgency=high . * Add patches for following CVEs - CVE-2013-1845: Remotely triggered memory exhaustion in mod_dav_svn (Closes: #704940) - CVE-2013-1846: Remotely triggered crash in mod_dav_svn - CVE-2013-1847: Remotely triggered crash in mod_dav_svn - CVE-2013-1849: Remotely triggered crash in mod_dav_svn - CVE-2014-0032: mod_dav_svn crash when handling certain requests with SVNListParentPath on (Closes: #737815) - CVE-2015-0248: Assertion DoS vulnerability for certain mod_dav_svn and svnserve requests with dynamically evaluated revision numbers - CVE-2015-0251: mod_dav_svn allows spoofing svn:author property values for new revisions Checksums-Sha1: f23775c17a45ecc3de62c9e6a0eb7cf8a9d9bd1c 2291 subversion_1.6.12dfsg-7+deb6u2.dsc 73539896c51cd822678ef357a93a0875d671f5f8 114692 subversion_1.6.12dfsg-7+deb6u2.diff.gz f21ace67fb26b9ce4068b8e64561b2fe123d1afc 1964432 libsvn-doc_1.6.12dfsg-7+deb6u2_all.deb 82efa7ff03377c8ae543cab50f360d216dc73933 220098 subversion-tools_1.6.12dfsg-7+deb6u2_all.deb e0ced674a1a9e2d1e55a8e0bdce5855a38f8a17f 766 libsvn-ruby_1.6.12dfsg-7+deb6u2_all.deb 57881d0e0f1b9df2f441c17a8dcdaa7844af98cb 1312974 subversion_1.6.12dfsg-7+deb6u2_amd64.deb c5410687ff7beec9863a8d49cbb9d775eda2a332 980250 libsvn1_1.6.12dfsg-7+deb6u2_amd64.deb c9573d940fc3328f43886e71fd0bc15f78799736 1354486 libsvn-dev_1.6.12dfsg-7+deb6u2_amd64.deb 2888df945f23c6acd6519ac2e3d935a0203139fd 167264 libapache2-svn_1.6.12dfsg-7+deb6u2_amd64.deb 178facd7725b5dbe30e0cf2ccbad1f72e327fcba 1324598 python-subversion_1.6.12dfsg-7+deb6u2_amd64.deb bfe3eb1dec5b906e7fd8e970448ca603454df118 305096 libsvn-java_1.6.12dfsg-7+deb6u2_amd64.deb bf56285f5a2d42eb4faf76cdff2662ab44db1aa2 1176248 libsvn-perl_1.6.12dfsg-7+deb6u2_amd64.deb 455180a46c33669499b049c0a3a6c0821818b781 609746 libsvn-ruby1.8_1.6.12dfsg-7+deb6u2_amd64.deb Checksums-Sha256: a435d226473d9afd827a76168f36c66636757c1ecdfd30a656f7ce3858c5a163 2291 subversion_1.6.12dfsg-7+deb6u2.dsc 353899bc0fd1f213d28cd92a99d115b4fcac9b48779b690d75c694c0957a9dda 114692 subversion_1.6.12dfsg-7+deb6u2.diff.gz cd0146b2befafbc2071caab65730adb494ee33110cc4caaebf66452d8230bdbe 1964432 libsvn-doc_1.6.12dfsg-7+deb6u2_all.deb 7692cdb73a9a5f1075e472d01459b6e71b7c5008c876afeca301a9f25a2333fb 220098 subversion-tools_1.6.12dfsg-7+deb6u2_all.deb 118f25a83931a2f131a3a77ae6f00465d7b16879c2ba4e562b9f47d7a2caff64 766 libsvn-ruby_1.6.12dfsg-7+deb6u2_all.deb 0999c58cf1d1db236b0466c02d8bb81631ffd7a9e069640f26818ebfc1e1796e 1312974 subversion_1.6.12dfsg-7+deb6u2_amd64.deb 656c565dec72ac5d737e9e281e77df1df12a712e4cb6617d990fab6deae8a590 980250 libsvn1_1.6.12dfsg-7+deb6u2_amd64.deb e63984492134e43f36db457377e62e7cf5e077b07830b948b6d6a9a6010620a3 1354486 libsvn-dev_1.6.12dfsg-7+deb6u2_amd64.deb d232e4266699b39595809725c8cd32e9f79744a8b8c95fa4f932f7b8dab0cee8 167264 libapache2-svn_1.6.12dfsg-7+deb6u2_amd64.deb 43194918ea440dd9879363ab75b1799a4f94d5014d750a1562474e101ec515f3 1324598 python-subversion_1.6.12dfsg-7+deb6u2_amd64.deb 8356cac00b5b0406770e2bccc1ea503268c014bc1b465e2e575d72ebdc1bc202 305096 libsvn-java_1.6.12dfsg-7+deb6u2_amd64.deb 71270551603b702bbcf8c04c80e08c1e5a1fc2abc77217fba07c335738c2e2c7 1176248 libsvn-perl_1.6.12dfsg-7+deb6u2_amd64.deb 4ca26e76faa692d1d0e9fb9e7f97745d748597a6bc66f818d707944d9571d4d0 609746 libsvn-ruby1.8_1.6.12dfsg-7+deb6u2_amd64.deb Files: 197d94556ff250d1c4995343430cf7f5 2291 vcs optional subversion_1.6.12dfsg-7+deb6u2.dsc ff80f6b7a849ed3eed58b3aa4df389b0 114692 vcs optional subversion_1.6.12dfsg-7+deb6u2.diff.gz 4a95a0a1de1fe8a905d60d86cdf51b8c 1964432 doc extra libsvn-doc_1.6.12dfsg-7+deb6u2_all.deb c4fb564c53a6eefaeb34ed0f87cea979 220098 vcs extra subversion-tools_1.6.12dfsg-7+deb6u2_all.deb 734ac6af84a0ea259846833aea566ce0 766 ruby optional libsvn-ruby_1.6.12dfsg-7+deb6u2_all.deb 6bdbace1b2bc695d4c6591c4292e6fca 1312974 vcs optional subversion_1.6.12dfsg-7+deb6u2_amd64.deb 6a8d70a478d16205767e4b8c1f02aa58 980250 vcs optional libsvn1_1.6.12dfsg-7+deb6u2_amd64.deb c22b6e63acecc2740209b9e7da4054c2 1354486 vcs extra libsvn-dev_1.6.12dfsg-7+deb6u2_amd64.deb 62c74829747da912e544bd5af8a6142d 167264 httpd optional libapache2-svn_1.6.12dfsg-7+deb6u2_amd64.deb b6dcfa1d366a6eb70a97c41cb9c95049 1324598 python optional python-subversion_1.6.12dfsg-7+deb6u2_amd64.deb fbb9e88fb6495aefa0a3e4864c6e502a 305096 java optional libsvn-java_1.6.12dfsg-7+deb6u2_amd64.deb ca6c3f7664bacb42d35ffe1973057cb8 1176248 perl optional libsvn-perl_1.6.12dfsg-7+deb6u2_amd64.deb ea771d2aad286f695eed487acf1044ff 609746 ruby optional libsvn-ruby1.8_1.6.12dfsg-7+deb6u2_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 Comment: Signed by Raphael Hertzog iQEcBAEBCAAGBQJVOgsfAAoJEAOIHavrwpq5SwIIALtyMmlhcyAYNpTLpB9SP/oS Ts0RckCDoGJhbVm1ND5IBYBo+wJBtcfoS9vy2/vGeGLg8bpna9k+fHlPMvEODRCG F/iuFa66eurwkI0TqoErP7HZechzjI/ehEt7ZcVYW6qSsZ5/ieHT7rLWfeGM9eGE w2y0O7EAg3jJYhh40n9iHPLnwz0tmRmptNT3o516j5HzU6AdfSdZearZd5m9dHdo nu/3txrYW6q3FCDvO7CoicZrWyjDBO4u7TYtj0GpDaFZuL5VYZFekl9ThTiX7XCQ mQQNpNiWBOudicpwiJYI43ieQl7nqaPgfU2divvEEXa51gqrxYylIhYGWa+HDEg= =vgRb -----END PGP SIGNATURE-----