-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 09 Aug 2017 21:08:28 -0400 Source: subversion Binary: subversion subversion-dbg libsvn1 libsvn-dev libsvn-doc libapache2-mod-svn libapache2-svn python-subversion subversion-tools libsvn-java libsvn-perl ruby-svn libsvn-ruby1.8 Architecture: source all amd64 Version: 1.8.10-6+deb8u5 Distribution: jessie-security Urgency: high Maintainer: Peter Samuelson <peter@p12n.org> Changed-By: James McCoy <jamessan@debian.org> Description: libapache2-mod-svn - Apache Subversion server modules for Apache httpd libapache2-svn - Apache Subversion server modules for Apache httpd (dummy package) libsvn-dev - Development files for Apache Subversion libraries libsvn-doc - Developer documentation for libsvn libsvn-java - Java bindings for Apache Subversion libsvn-perl - Perl bindings for Apache Subversion libsvn-ruby1.8 - Ruby bindings for Apache Subversion (dummy package) libsvn1 - Shared libraries used by Apache Subversion python-subversion - Python bindings for Apache Subversion ruby-svn - Ruby bindings for Apache Subversion subversion - Advanced version control system subversion-dbg - Debug symbols for Apache Subversion subversion-tools - Assorted tools related to Apache Subversion Changes: subversion (1.8.10-6+deb8u5) jessie-security; urgency=high . * patches/CVE-2016-8734: Unrestricted XML entity expansion in HTTP clients * patches/CVE-2017-9800: Arbitrary code execution on clients through malicious svn+ssh URLs in svn:externals and svn:sync-from-url Checksums-Sha1: 7661692056bb5943c17192591fdbd26dd7986dab 3165 subversion_1.8.10-6+deb8u5.dsc 499ae5d96010f562b790f40bfe125172663d4d27 301259 subversion_1.8.10-6+deb8u5.diff.gz d6fd2d469725f39500913b9459926b4b8a915570 1407240 libsvn-doc_1.8.10-6+deb8u5_all.deb 1dc9d7fb0dcb44846246385235505797bacd09ef 125438 libapache2-svn_1.8.10-6+deb8u5_all.deb 37e64694f1cf12baa9ba172375ca20e2f2c195fa 1030 libsvn-ruby1.8_1.8.10-6+deb8u5_all.deb f640c71333522edf0cfaf0c0a9e1647a78f532ef 922732 subversion_1.8.10-6+deb8u5_amd64.deb 5be0ef9a8be9593ed43bf2ed689485d95099b5fa 7827274 subversion-dbg_1.8.10-6+deb8u5_amd64.deb adbae5209345e83b3c99f97c9712b238653d43d1 1075222 libsvn1_1.8.10-6+deb8u5_amd64.deb 2736f2554f21f1f5db2dd41255eca788b6990609 1214154 libsvn-dev_1.8.10-6+deb8u5_amd64.deb 4b81870bc438c94016802c330ff4e4e6d3b70e8a 200670 libapache2-mod-svn_1.8.10-6+deb8u5_amd64.deb 232039732bde5e847e7ae39de4f526a546584500 649512 python-subversion_1.8.10-6+deb8u5_amd64.deb 34fa351e75827e9062d2f0e49ceee80317a366ab 322430 subversion-tools_1.8.10-6+deb8u5_amd64.deb ad51b40e0ae4d23f5c591d1674d74e94b1239c8d 350754 libsvn-java_1.8.10-6+deb8u5_amd64.deb a57766b34dcd59f7faeace77d392bb27fe7e7b61 939368 libsvn-perl_1.8.10-6+deb8u5_amd64.deb 7c5a50b331eb042ae37bc09c220141b9338c4f3e 561676 ruby-svn_1.8.10-6+deb8u5_amd64.deb Checksums-Sha256: 6ce18f5a85d347bf8b7e6928fce2409b52287d77943ca3e328d76070cce7d2ec 3165 subversion_1.8.10-6+deb8u5.dsc 739293101d9cc5e2b556c7871fc787255970230835155836edd692848fb76819 301259 subversion_1.8.10-6+deb8u5.diff.gz dcd3c2915cfb06d5ec5ff034098c862296cafe858f9ebb9a9f973486f5281044 1407240 libsvn-doc_1.8.10-6+deb8u5_all.deb 39025a609838929f4d7617df02c7a0b09fb2eca9cee5a201a54a917bdfaf43bb 125438 libapache2-svn_1.8.10-6+deb8u5_all.deb 79b17983a517d6c4b0803c6891aaf38cfcfa008f6a08865677b25c9a87eb4fee 1030 libsvn-ruby1.8_1.8.10-6+deb8u5_all.deb 5b0f37369d340216c0a1e5ec3c8d132fea6bf4eb211ebe54972fdb3afea3af3f 922732 subversion_1.8.10-6+deb8u5_amd64.deb 53a2136cd13d69ae9e18dc71b0a99fc3564eb33efd444a464c364149f3308134 7827274 subversion-dbg_1.8.10-6+deb8u5_amd64.deb c79cbe8321d995666bc419e992632ca158ebbcf3bca9530866d7e4bb85bc392b 1075222 libsvn1_1.8.10-6+deb8u5_amd64.deb f6e0a1bf4dcc3e45926889437239b9631a210426221e8e67f7930e19b2f04f47 1214154 libsvn-dev_1.8.10-6+deb8u5_amd64.deb a6c0508e2605e789b333d4a4a5eceff664e6c16692eac5ab237ac29644f073c1 200670 libapache2-mod-svn_1.8.10-6+deb8u5_amd64.deb fee55308256ad9a956ad172e909bd5d99355df274a9a4d96fe7d6711e2d26d38 649512 python-subversion_1.8.10-6+deb8u5_amd64.deb ab124ac65dec60a887946b094f2edb504378ebdd2090b5a989a4b02eeb946027 322430 subversion-tools_1.8.10-6+deb8u5_amd64.deb 69a9849160376020de9b6b9091057e5de6560d3102cb6de02413246dee88d3e4 350754 libsvn-java_1.8.10-6+deb8u5_amd64.deb 109372cb0068cb2b8106fac4d2f28ffbf56d61a1ee9a00f9f2eb63fa17ab0ec5 939368 libsvn-perl_1.8.10-6+deb8u5_amd64.deb e20a52b9c09059f2175e23c5ef4cc9e7de2d004807584f7e6a1702aeb816ac36 561676 ruby-svn_1.8.10-6+deb8u5_amd64.deb Files: 20af46a2ad8b6425c7a7e8c894e3fb5a 3165 vcs optional subversion_1.8.10-6+deb8u5.dsc 905c307d32c58626792f18e3577fda99 301259 vcs optional subversion_1.8.10-6+deb8u5.diff.gz c86731f46b92ed731bbe3db09e7524cd 1407240 doc extra libsvn-doc_1.8.10-6+deb8u5_all.deb 565b0746b624282d123b21cb38d0d482 125438 oldlibs extra libapache2-svn_1.8.10-6+deb8u5_all.deb 6aa63d7ab03904e105a4020ebab3501c 1030 oldlibs extra libsvn-ruby1.8_1.8.10-6+deb8u5_all.deb 52be6f61db7426b713a1b0997850ba11 922732 vcs optional subversion_1.8.10-6+deb8u5_amd64.deb f6d59c9c5cd69d51066b026d75dec49a 7827274 debug extra subversion-dbg_1.8.10-6+deb8u5_amd64.deb d8bd0fa4281623a1617b86feea38284e 1075222 libs optional libsvn1_1.8.10-6+deb8u5_amd64.deb 8e2c11d30f47abc8082f926b48888933 1214154 libdevel extra libsvn-dev_1.8.10-6+deb8u5_amd64.deb 9692b7b4365bb64cf1fa084b395af322 200670 httpd optional libapache2-mod-svn_1.8.10-6+deb8u5_amd64.deb 471c6ddcce89a26fe9a2d66401540e9e 649512 python optional python-subversion_1.8.10-6+deb8u5_amd64.deb ee63ddf9754070af4b30722e15179515 322430 vcs extra subversion-tools_1.8.10-6+deb8u5_amd64.deb cd6cf31783ed613fdea11fb2f2690a9a 350754 java optional libsvn-java_1.8.10-6+deb8u5_amd64.deb 4496d048da6ec721fa2e8613b3bfff88 939368 perl optional libsvn-perl_1.8.10-6+deb8u5_amd64.deb 888964e9926d8ea7d00b6fe20651fbfc 561676 ruby optional ruby-svn_1.8.10-6+deb8u5_amd64.deb -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEEkb+/TWlWvV33ty0j3+aRrjMbo9sFAlmMhbpfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDkx QkZCRjRENjk1NkJENURGN0I3MkQyM0RGRTY5MUFFMzMxQkEzREIACgkQ3+aRrjMb o9uhvg/+Igm8vJlqxZGSitxJ4DYhl8y9AbR40NC82uLY3jIMPSFNo+nzWejHCCoQ J4OGk6lK629tNv0FBuJgboDZlpXDtODMmumLjmf2oHu54tO3SlpYPZg89BMovhOl iJjSAL0K35obdRp1GKYLV/uFTh8ep+HgYD6PgKKO2gjOZFkkeWCJ8Jho9gwDXr6I aHK7Jb1yxf0CWkV7hW5ZOhxfImjPcbMJqFzv2R7nWcbgu67pmzoxD1IGqYqugTDP amwdYLqd01+fRcSFy88+lFdXdytlJ83N5j5uw8G5r9q2luOBwXSyAnoduhNl4CVf Ggv5sJwWliUzcheNft4aMtCH3DoPR8hyo4vH9V9ygN0RKb5OGeJBDwGlvUX9zqsr O15gUXQwx3d9SAGSH7PwdARafxOLVxQmqgycSj+zWe1PIRMZ89XxZdkO1/WbGK/I kq+jpJuXRYioG5jQ8wlO/2p59saPHGMoqWltoSuICfEW7JCk8VUKUIFwp98/ObcE MoRO5mLVgqrcizZO0TF1Ct4XCVu9uUvWnKbyZ+s9kROmhGdXc++r2A2xM90j2Z0e crPERLddF+++amFGaT+6sT4arKq4zeSzPjxo0lJzt36EImm3wu70r1mgLSUEyguw SDRALgN0gMabEWmN/+80htx7YpTn8t4x95Po5qi5H+5s0Elh2T0= =lhTf -----END PGP SIGNATURE-----