File:  [cvs.NetBSD.org] / pkgsrc / devel / subversion / distinfo
Revision 1.121: download - view: text, annotated - select for diffs
Wed Oct 9 21:15:42 2024 UTC (5 months, 2 weeks ago) by bsiegert
Branches: MAIN
CVS tags: pkgsrc-2024Q4-base, pkgsrc-2024Q4, HEAD
subversion: update to 1.14.4

This is a security release but the issue is Windows-only AFAICT.

This is a stable bugfix and security release of the Apache Subversion
open source version control system.

Among regular bug fixes, this release fixes CVE-2024-45720:

   Subversion command line argument injection on Windows platforms

   On Windows platforms, a "best fit" character encoding conversion of
   command line arguments to Subversion's executables (e.g., svn.exe,
   etc.) may lead to unexpected command line argument interpretation,
   including argument injection and execution of other programs, if a
   specially crafted command line argument string is processed.

   UNIX-like platforms are not affected.

   Reported by:
   Orange Tsai and splitline from DEVCORE Research Team

   Full advisory:
   https://subversion.apache.org/security/CVE-2024-45720-advisory.txt
   https://subversion.apache.org/security/CVE-2024-45720-advisory.txt.asc

$NetBSD: distinfo,v 1.121 2024/10/09 21:15:42 bsiegert Exp $

BLAKE2s (subversion-1.14.4.tar.bz2) = 731560d0576fde94b7bacbe2a1c055cecbecab9a936488f8d7b5eb335b916ebb
SHA512 (subversion-1.14.4.tar.bz2) = f5e104ef20c96f2605965fafeb9245b03c722734031c2c8d2b6f996979624566ac0a5dadc2d37274a360f2b1dbecb9f7149d0a43c23c2616b9176d0b9367c924
Size (subversion-1.14.4.tar.bz2) = 8509652 bytes
SHA1 (patch-Makefile.in) = 378336a0908c28bf70b33833d23955ce0d562b12
SHA1 (patch-configure) = c1c73ace0b28acb921189bd97b74459823a2b104
SHA1 (patch-subversion_bindings_swig_perl_native_Makefile.PL.in) = 3fadde312693f2a304cd7e348c66cbd373c57854
SHA1 (patch-tools_dev_benchmarks_large__dirs_create__bigdir.sh) = ff19087ff4d348fdcf904eb52406f6b717fe444a

CVSweb <webmaster@jp.NetBSD.org>