<rt id="bn8ez"></rt>
<label id="bn8ez"></label>

  • <span id="bn8ez"></span>

    <label id="bn8ez"><meter id="bn8ez"></meter></label>

    網路冷眼@BlogJava

    熙熙攘攘一閑人 以冷靜的眼光觀察技術
    posts - 88, comments - 193, trackbacks - 0, articles - 28
      BlogJava :: 首頁 :: 新隨筆 :: 聯系 :: 聚合  :: 管理

    Subversion 1.4.5 Released

    Posted on 2007-08-29 09:22 網路冷眼@BlogJava 閱讀(861) 評論(0)  編輯  收藏 所屬分類: Software Engineering

    Subversion 1.4.5 Released

    August 27, 2007

    Subversion 1.4.5 was released today.  You can download the updated CollabNet Subversion binaries immediately.

    Subversion 1.4.5 contains a fix for a security exploit on Windows clients. This exploit was discovered and reported by researchers at the Colorado Research Institute for Security and Privacy.

    The only change from Subversion 1.4.4 is the patch for this security exploit.  Since the exploit only affects Windows clients, we decided to only release CollabNet Subversion 1.4.5 packages for Windows. There is no point for someone who is already running 1.4.4 on any other operating system to update to 1.4.5.

    I am not going to give a lot of details about the exploit, you can find more information at various security reporting sites, such as CVE.  I will say that it was a legitimate exposure that made it possible for the Subversion client to write files outside the normal working copy.  That being said, there are a couple of points to make:

    1. Creating the exploit requires commit access to the repository.  If you can trust the people who have write access to the repository, then you do not have too much to be concerned about. The keyword in that sentence is "trust". If you are checking out from a repository you cannot completely trust, such as on a public hosting service, then be careful and update to 1.4.5 first.
    2. While the exploit itself is pretty easy to produce, it is also pretty difficult to use it in a way that would cause harm.
    3. You can only create the exploit from a non-Windows platform.
    4. There is nothing terribly secretive about the exploit.  If you send commit emails, or even just browse your repository using svn ls, this exploit would stand out as not normal.

    If you are running a Subversion client on Windows, this would include the command line client as well as any graphical client such as TortoiseSVN or Subclipse, then you should definitely go ahead and install this version of Subversion.  I would recommend that users of earlier versions such as 1.3.2 or 1.2.3 also install this update immediately. The Subversion 1.4.5 client can talk to any 1.x version of the server, so there is no reason not to update your client (for compatibility: if you have the command line and a GUI client, update them both).

    Subversion servers are not affected by this exploit.  That being said, a Windows server that uses the Subversion client in scripts would still be vulnerable and should be updated to 1.4.5.

    http://blogs.open.collab.net/svn/2007/08/subversion-145-.html

    主站蜘蛛池模板: 国产精品亚洲片在线| 亚洲国产系列一区二区三区 | 亚洲午夜精品一区二区| 亚洲特级aaaaaa毛片| 免费无遮挡无码视频在线观看| 免费污视频在线观看| 免费看的一级毛片| 久久亚洲精品中文字幕无码| 亚洲av日韩av永久在线观看| 一级毛片免费观看不卡的| 免费人成在线观看视频播放| 亚洲精品影院久久久久久| 最近免费中文在线视频| 久久久久无码精品亚洲日韩| 国产无遮挡无码视频免费软件| 亚洲成AV人片在线观看WWW| 狠狠入ady亚洲精品| 在线观看av永久免费| 久久久亚洲欧洲日产国码aⅴ | 91视频免费观看高清观看完整| 在线精品免费视频| 亚洲精品福利网站| 91免费资源网站入口| 日本系列1页亚洲系列| 中文字幕中韩乱码亚洲大片| 香蕉视频免费在线播放| 免费高清小黄站在线观看| 美女视频免费看一区二区| 亚洲欧洲成人精品香蕉网| 免费高清A级毛片在线播放| 亚洲真人无码永久在线| 一区二区免费国产在线观看| 国产成人综合久久精品免费| 自拍日韩亚洲一区在线| 麻豆视频免费播放| 91亚洲国产成人久久精品网址| 99精品视频免费观看| 久久亚洲精品成人av无码网站| 最近免费中文字幕视频高清在线看| 亚洲黄色免费电影| 1000部国产成人免费视频|