-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 27 Apr 2016 20:00:25 -0400 Source: subversion Binary: subversion subversion-dbg libsvn1 libsvn-dev libsvn-doc libapache2-mod-svn libapache2-svn python-subversion subversion-tools libsvn-java libsvn-perl ruby-svn libsvn-ruby1.8 Architecture: source all amd64 Version: 1.8.10-6+deb8u4 Distribution: jessie-security Urgency: high Maintainer: Peter Samuelson <peter@p12n.org> Changed-By: James McCoy <jamessan@debian.org> Description: libapache2-mod-svn - Apache Subversion server modules for Apache httpd libapache2-svn - Apache Subversion server modules for Apache httpd (dummy package) libsvn-dev - Development files for Apache Subversion libraries libsvn-doc - Developer documentation for libsvn libsvn-java - Java bindings for Apache Subversion libsvn-perl - Perl bindings for Apache Subversion libsvn-ruby1.8 - Ruby bindings for Apache Subversion (dummy package) libsvn1 - Shared libraries used by Apache Subversion python-subversion - Python bindings for Apache Subversion ruby-svn - Ruby bindings for Apache Subversion subversion - Advanced version control system subversion-dbg - Debug symbols for Apache Subversion subversion-tools - Assorted tools related to Apache Subversion Changes: subversion (1.8.10-6+deb8u4) jessie-security; urgency=high . + patches/CVE-2016-2167: svnserve/sasl may authenticate users using the wrong realm + patches/CVE-2016-2168: Remotely triggerable DoS vulnerability in mod_authz_svn during COPY/MOVE authorization check Checksums-Sha1: eb1524c8e3c8740b3bd7001a770b12f23ca8e316 3151 subversion_1.8.10-6+deb8u4.dsc 73e2552f21a1e39cd0b32a01e2a3bd7a2664f6a1 298630 subversion_1.8.10-6+deb8u4.diff.gz 4c29392e8465187a08d11828b73a476300599fbf 1407188 libsvn-doc_1.8.10-6+deb8u4_all.deb b4e5986d00efefc602471b892d7159208cca9aaf 125350 libapache2-svn_1.8.10-6+deb8u4_all.deb 4864ab64424c2350f8af1ca77b977705efc2ef55 1028 libsvn-ruby1.8_1.8.10-6+deb8u4_all.deb 57f4f9947129b36165c2e95dce5857335acffdaa 922504 subversion_1.8.10-6+deb8u4_amd64.deb 85f3db96e02ac65080b3fa38c4fef3dc98afd96d 7834846 subversion-dbg_1.8.10-6+deb8u4_amd64.deb 1336c885afb102d02371b4a45cd750e09ac427b6 1076386 libsvn1_1.8.10-6+deb8u4_amd64.deb f5b3740ef79c27e56c591525dc6abc4191735e80 1213702 libsvn-dev_1.8.10-6+deb8u4_amd64.deb 29ac88b987115d8c0409e8479fb2f49305446212 200758 libapache2-mod-svn_1.8.10-6+deb8u4_amd64.deb 3ebbc63c401d9a17a939ffa72fd93e7655323bc7 648420 python-subversion_1.8.10-6+deb8u4_amd64.deb f16072cc01a11185ac13db216f145895638aac8f 322280 subversion-tools_1.8.10-6+deb8u4_amd64.deb f71c88935b2f20c3306350ef24fbfa92387c1c13 351162 libsvn-java_1.8.10-6+deb8u4_amd64.deb a8fcefe34003b96c603baea74eb778c43327fc09 936202 libsvn-perl_1.8.10-6+deb8u4_amd64.deb f8eaa388ab79b76a40c1a86037acb8c1e6fbc4af 561908 ruby-svn_1.8.10-6+deb8u4_amd64.deb Checksums-Sha256: dd3ff32ccd58bd737cb70df7bc79ffb1fe5ce34a01531267702e62fbfa88a7d2 3151 subversion_1.8.10-6+deb8u4.dsc bf4ff9dec131a75fb438336838c1c0db75c8b0760dc957110ecea807505f8d24 298630 subversion_1.8.10-6+deb8u4.diff.gz f7036a54fd2280741c31d615cfd6f3b0a15949a15ba5babc86afbdb605ef755c 1407188 libsvn-doc_1.8.10-6+deb8u4_all.deb eb6ad053555887987d64641d8fe257e32f75c65affa43b951545fffab841dc9f 125350 libapache2-svn_1.8.10-6+deb8u4_all.deb 687fac0553a52afd8866d1c630d7767b9edf9f93cbfe7f566d4c066a93e9cc74 1028 libsvn-ruby1.8_1.8.10-6+deb8u4_all.deb 547a3c24f9af66c1eb1de50b04c351ed285be9c68f40611b735adeef54020a9b 922504 subversion_1.8.10-6+deb8u4_amd64.deb 69000cc6b348dd9a0c92cb1fcd91a72bbaff0be26a26dbe22eb09fcb4278dd18 7834846 subversion-dbg_1.8.10-6+deb8u4_amd64.deb d2c73714486da8fe63351466ee18d6b3a3d6a701dba636fe0543c4c379321dff 1076386 libsvn1_1.8.10-6+deb8u4_amd64.deb fd80d49010f9f7d046727279b869cfc8c7e55b8c1867bf2c91c6f78239ac93f3 1213702 libsvn-dev_1.8.10-6+deb8u4_amd64.deb a5952070ba1edac2cce8a95fd94c211c4bf2bc053ead8bf4093ed5ab9a8f0c3f 200758 libapache2-mod-svn_1.8.10-6+deb8u4_amd64.deb f67c23e81774ea2e32cbccd34d757296e0a2d184a3ad3dc98368d777269e23c2 648420 python-subversion_1.8.10-6+deb8u4_amd64.deb d6d56c02e9b671577871b7fb8a0fb224b17099461e2bb84fa75c196f5b03525e 322280 subversion-tools_1.8.10-6+deb8u4_amd64.deb d3c42282c67257850fd89a52b5073ec23201282bb56e82879cd7abae9f785f5a 351162 libsvn-java_1.8.10-6+deb8u4_amd64.deb 02d2012f0d556b0c591cc0c109dc9044cbf3e804e36a04c55538812b14a2265b 936202 libsvn-perl_1.8.10-6+deb8u4_amd64.deb ce08ea588a0a2df1dd06e4a103dd03501fb09ea31b2237fcae49c132af39231d 561908 ruby-svn_1.8.10-6+deb8u4_amd64.deb Files: 001353a73f8f11f662fd8d82868592cd 3151 vcs optional subversion_1.8.10-6+deb8u4.dsc 53f00b7a59619aed7661eb63f95d8599 298630 vcs optional subversion_1.8.10-6+deb8u4.diff.gz 8f7d0e3ac875b9ad51986cd944668d6c 1407188 doc extra libsvn-doc_1.8.10-6+deb8u4_all.deb 214772714ebd6b725fbe0f4df2ea26f8 125350 oldlibs extra libapache2-svn_1.8.10-6+deb8u4_all.deb 0e29b96c4b6ddf894db775be566cef9e 1028 oldlibs extra libsvn-ruby1.8_1.8.10-6+deb8u4_all.deb 8282cf53bf58912075b0bb4ac39140e9 922504 vcs optional subversion_1.8.10-6+deb8u4_amd64.deb 97a5fce6f344159322110b17d4f336ee 7834846 debug extra subversion-dbg_1.8.10-6+deb8u4_amd64.deb a8373103b460112e7b2d6f5c5259c54e 1076386 libs optional libsvn1_1.8.10-6+deb8u4_amd64.deb a7ed079974201e46a3dc1312b2049a37 1213702 libdevel extra libsvn-dev_1.8.10-6+deb8u4_amd64.deb 5714f19a00a0da20b366c674c0c1e079 200758 httpd optional libapache2-mod-svn_1.8.10-6+deb8u4_amd64.deb 55a65355c9708c85706b4a31d68ea7b5 648420 python optional python-subversion_1.8.10-6+deb8u4_amd64.deb 501046a6e1516e5cbcc6fd25cdd5ff5a 322280 vcs extra subversion-tools_1.8.10-6+deb8u4_amd64.deb a91b464b1803408f9b4e704a51c1be83 351162 java optional libsvn-java_1.8.10-6+deb8u4_amd64.deb b39c988a33f0d3ed9abf9a2c762d0197 936202 perl optional libsvn-perl_1.8.10-6+deb8u4_amd64.deb a21545471627d1d902a9892fe7f14a15 561908 ruby optional ruby-svn_1.8.10-6+deb8u4_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQJ8BAEBCgBmBQJXIfINXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQ5MUJGQkY0RDY5NTZCRDVERjdCNzJEMjNE RkU2OTFBRTMzMUJBM0RCAAoJEN/mka4zG6PbpL4P/2vvGJ3Xgc3ron2YWnDPnzqn ZFBMX4VOlze94lqDIayIgKa3VBomvqvK7gNIanfqL6jinGyhFEI4pn2KV9rxV18M Y+1qkkjKahmLGgpzb/qJzQzyWqray79H+Ti/thmGPaPgQvtnOsEx5ICUBSQ8seAs h5qmQ7TdNKOOTyhH5xoTApJWjParg3Kb/cejVtXjrXdqzEXjV0jA5ZT6CetKNmwm +cdT6zsekgOcwrT4fkZtTtRW4AGIVRIKt2t6cftVedvJ+QZfRjosNPBztiWvyCrY Z25gGidwFHbr0olT/++AbCEhQmuWOCurV/zESOutEbNpGBk7ej2TpGwdWCbiBYiH z0HBJV1VxVeS4djOI/vCSKDtYg4ZVCS4szYrzyfDWXvA0mCj6xvHaXsUkhEuEeKv bxdFqyKn+eqnLVuNovDJ3RX7srrLWVvlTcyepVVDUQwJlGfq0KlXS1KG6CgIfRp+ JAtUKwiMNKTcAPxcFpl+tbJ+aExjE1jmIwyAdFu63FfyoUJW5E4nJZvdjfnjgBal XeVWC7krfIPHPviFKuOSWFRuiA5OtxnnvV+xjw0O9GnNKNzu8Ml5qiVemdylX3Gw lYUxsVplDZ2Bj2ULF3Fqg1rqt0KrFpv0MLXpVHCNuK4Bxag81esMK9W5LXZlKa6p 6EqIHuwacycLaAo0iyBm =A0Rp -----END PGP SIGNATURE-----