You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@subversion.apache.org by Lübbe Onken <l....@rac.de> on 2004/10/11 08:16:04 UTC
Subversion on SANS Top twenty list
Hi Folks,
has anybody read this:
http://www.sans.org/top20/#u4
a section about vulnerabilities in svnserve? And is this still true?
Cheers
- Lübbe
--
___
oo // \\ "De Chelonian Mobile"
(_,\/ \_/ \ TortoiseSVN
\ \_/_\_/> The coolest Interface to (Sub)Version Control
/_/ \_\ http://tortoisesvn.tigris.org
---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@subversion.tigris.org
For additional commands, e-mail: dev-help@subversion.tigris.org
Re: Subversion on SANS Top twenty list
Posted by Ben Reser <be...@reser.org>.
On Mon, Oct 11, 2004 at 10:16:04AM +0200, Lübbe_Onken wrote:
> has anybody read this:
> http://www.sans.org/top20/#u4
> a section about vulnerabilities in svnserve? And is this still true?
Blah. Remind me never to coordinate a release date on security stuff
with the CVS people again. Once again people are lumping our issue
together with the CVS issue simply because it was fixed/released on the
same day.
CVS belongs in the top 20. But we sure don't. As much as we'd like to
think Subversion has that type of market share, I just don't believe
that it's true.
So I can only conclude that we're included due to the timing and
publicity that the CVS issue got. If we'd released our fix a couple
days earlier or a couple days later, I bet we wouldn't even be on the
list.
--
Ben Reser <be...@reser.org>
http://ben.reser.org
"Conscience is the inner voice which warns us somebody may be looking."
- H.L. Mencken
---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@subversion.tigris.org
For additional commands, e-mail: dev-help@subversion.tigris.org
Re: Subversion on SANS Top twenty list
Posted by kf...@collab.net.
Lübbe Onken <l....@rac.de> writes:
> http://www.sans.org/top20/#u4
>
> a section about vulnerabilities in svnserve? And is this still true?
It referred to old versions of 'svnserve'. The vulnerabilities do not
exist in later versions.
---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@subversion.tigris.org
For additional commands, e-mail: dev-help@subversion.tigris.org