You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@subversion.apache.org by Lübbe Onken <l....@rac.de> on 2004/10/11 08:16:04 UTC

Subversion on SANS Top twenty list

Hi Folks,

has anybody read this:

http://www.sans.org/top20/#u4

a section about vulnerabilities in svnserve? And is this still true?

Cheers
- Lübbe

--
        ___
   oo  // \\      "De Chelonian Mobile"
  (_,\/ \_/ \     TortoiseSVN
    \ \_/_\_/>    The coolest Interface to (Sub)Version Control
    /_/   \_\     http://tortoisesvn.tigris.org


---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@subversion.tigris.org
For additional commands, e-mail: dev-help@subversion.tigris.org

Re: Subversion on SANS Top twenty list

Posted by Ben Reser <be...@reser.org>.
On Mon, Oct 11, 2004 at 10:16:04AM +0200, Lübbe_Onken wrote:
> has anybody read this:
> http://www.sans.org/top20/#u4
> a section about vulnerabilities in svnserve? And is this still true?

Blah.  Remind me never to coordinate a release date on security stuff
with the CVS people again.  Once again people are lumping our issue
together with the CVS issue simply because it was fixed/released on the
same day.  

CVS belongs in the top 20.  But we sure don't.  As much as we'd like to
think Subversion has that type of market share, I just don't believe
that it's true.

So I can only conclude that we're included due to the timing and
publicity that the CVS issue got.  If we'd released our fix a couple
days earlier or a couple days later, I bet we wouldn't even be on the
list.

-- 
Ben Reser <be...@reser.org>
http://ben.reser.org

"Conscience is the inner voice which warns us somebody may be looking."
- H.L. Mencken

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@subversion.tigris.org
For additional commands, e-mail: dev-help@subversion.tigris.org

Re: Subversion on SANS Top twenty list

Posted by kf...@collab.net.
Lübbe Onken <l....@rac.de> writes:
> http://www.sans.org/top20/#u4
> 
> a section about vulnerabilities in svnserve? And is this still true?

It referred to old versions of 'svnserve'.  The vulnerabilities do not
exist in later versions.


---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@subversion.tigris.org
For additional commands, e-mail: dev-help@subversion.tigris.org