<rt id="bn8ez"></rt>
<label id="bn8ez"></label>

  • <span id="bn8ez"></span>

    <label id="bn8ez"><meter id="bn8ez"></meter></label>

    網(wǎng)路冷眼@BlogJava

    熙熙攘攘一閑人 以冷靜的眼光觀察技術
    posts - 88, comments - 193, trackbacks - 0, articles - 28
      BlogJava :: 首頁 :: 新隨筆 :: 聯(lián)系 :: 聚合  :: 管理

    Subversion 1.4.5 Released

    Posted on 2007-08-29 09:22 網(wǎng)路冷眼@BlogJava 閱讀(860) 評論(0)  編輯  收藏 所屬分類: Software Engineering

    Subversion 1.4.5 Released

    August 27, 2007

    Subversion 1.4.5 was released today.  You can download the updated CollabNet Subversion binaries immediately.

    Subversion 1.4.5 contains a fix for a security exploit on Windows clients. This exploit was discovered and reported by researchers at the Colorado Research Institute for Security and Privacy.

    The only change from Subversion 1.4.4 is the patch for this security exploit.  Since the exploit only affects Windows clients, we decided to only release CollabNet Subversion 1.4.5 packages for Windows. There is no point for someone who is already running 1.4.4 on any other operating system to update to 1.4.5.

    I am not going to give a lot of details about the exploit, you can find more information at various security reporting sites, such as CVE.  I will say that it was a legitimate exposure that made it possible for the Subversion client to write files outside the normal working copy.  That being said, there are a couple of points to make:

    1. Creating the exploit requires commit access to the repository.  If you can trust the people who have write access to the repository, then you do not have too much to be concerned about. The keyword in that sentence is "trust". If you are checking out from a repository you cannot completely trust, such as on a public hosting service, then be careful and update to 1.4.5 first.
    2. While the exploit itself is pretty easy to produce, it is also pretty difficult to use it in a way that would cause harm.
    3. You can only create the exploit from a non-Windows platform.
    4. There is nothing terribly secretive about the exploit.  If you send commit emails, or even just browse your repository using svn ls, this exploit would stand out as not normal.

    If you are running a Subversion client on Windows, this would include the command line client as well as any graphical client such as TortoiseSVN or Subclipse, then you should definitely go ahead and install this version of Subversion.  I would recommend that users of earlier versions such as 1.3.2 or 1.2.3 also install this update immediately. The Subversion 1.4.5 client can talk to any 1.x version of the server, so there is no reason not to update your client (for compatibility: if you have the command line and a GUI client, update them both).

    Subversion servers are not affected by this exploit.  That being said, a Windows server that uses the Subversion client in scripts would still be vulnerable and should be updated to 1.4.5.

    http://blogs.open.collab.net/svn/2007/08/subversion-145-.html

    主站蜘蛛池模板: 久久免费香蕉视频| www免费黄色网| 国产卡一卡二卡三免费入口| 亚洲最大成人网色| 永久在线免费观看| 亚洲日韩中文字幕天堂不卡| 99精品视频在线免费观看| 亚洲av综合色区| 日韩精品无码专区免费播放| 亚洲AV无码久久精品狠狠爱浪潮 | 在线观看免费视频资源| 亚洲国产精品久久久久网站 | a级在线免费观看| 久久亚洲精品国产精品黑人| 99精品视频在线观看免费播放| 亚洲神级电影国语版| 男女超爽刺激视频免费播放| 国产亚洲精品VA片在线播放| 国产亚洲精品免费| 岛国精品一区免费视频在线观看| 亚洲处破女AV日韩精品| 国产成人免费高清激情明星| 亚洲日日做天天做日日谢| 国产一区二区三区免费看| 国产精品免费久久| 亚洲欧洲日本国产| 国产嫩草影院精品免费网址| 国内精品99亚洲免费高清| 亚洲视频在线一区二区三区| 白白国产永久免费视频| 中文在线免费不卡视频| 亚洲国产精品人久久电影| 免费在线观看亚洲| 欧洲人成在线免费| 精品韩国亚洲av无码不卡区 | 亚洲av无码一区二区三区观看| 亚洲成年看片在线观看| 免费无码VA一区二区三区| 亚洲AV无码专区在线观看成人| 亚洲成A人片在线观看WWW| 最近2019中文字幕mv免费看|