You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@subversion.apache.org by Stefan Sperling <st...@apache.org> on 2021/02/10 15:26:22 UTC
[announce-owner@apache.org: Returned post for announce@apache.org]
Same thing as last time. Shrug.
I suppose next time I will just drop announce@ from Cc...
----- Forwarded message from announce-owner@apache.org -----
Date: 10 Feb 2021 15:20:01 -0000
From: announce-owner@apache.org
To: stsp@apache.org
Subject: Returned post for announce@apache.org
Message-ID: <16...@apache.org>
Content-Type: multipart/mixed; boundary=ibhjpejjlbghgodohoih
X-Spam-Score: (-7.502) SPF_HELO_PASS,SPF_PASS,USER_IN_DEF_SPF_WL
Hi! This is the ezmlm program. I'm managing the
announce@apache.org mailing list.
I'm working for my owner, who can be reached
at announce-owner@apache.org.
I'm sorry, your message (enclosed) was not accepted by the moderator.
If the moderator has made any comments, they are shown below.
>>>>> -------------------- >>>>>
Sorry, but the announce cannot be accepted.
The linked download page does not contain links for the version in the
email.
Also, the standard name for the KEYS file is KEYS - no prefix, no suffix.
Please correct the download page, check it, and submit a corrected announce
mail.
Thanks,
Sebb.
<<<<< -------------------- <<<<<
Date: Wed, 10 Feb 2021 14:36:33 +0100
From: Stefan Sperling <st...@apache.org>
To: announce@subversion.apache.org, users@subversion.apache.org,
dev@subversion.apache.org, announce@apache.org
Cc: security@apache.org, oss-security@lists.openwall.com,
bugtraq@securityfocus.com
Subject: [SECURITY][ANNOUNCE] Apache Subversion 1.14.1 released
Message-ID: <YC...@byrne.stsp.name>
Reply-To: users@subversion.apache.org
Content-Type: text/plain; charset=utf-8
I'm happy to announce the release of Apache Subversion 1.14.1.
Please choose the mirror closest to you by visiting:
https://subversion.apache.org/download.cgi#recommended-release
This is a stable bugfix and security release of the Apache Subversion
open source version control system.
THIS RELEASE CONTAINS AN IMPORTANT SECURITY FIX:
CVE-2020-17525
"Remote unauthenticated denial-of-service in Subversion mod_authz_svn"
The full security advisory for CVE-2020-17525 is available at:
https://subversion.apache.org/security/CVE-2020-17525-advisory.txt
A brief summary of this advisory follows:
Subversion's mod_authz_svn module will crash if the server is using
in-repository authz rules with the AuthzSVNReposRelativeAccessFile
option and a client sends a request for a non-existing repository URL.
This can lead to disruption for users of the service.
We recommend all users to upgrade to the 1.10.7 or 1.14.1 release
of the Subversion mod_dav_svn server.
As a workaround, the use of in-repository authz rules files with
the AuthzSVNReposRelativeAccessFile can be avoided by switching
to an alternative configuration which fetches an authz rules file
from the server's filesystem, rather than from an SVN repository.
This issue was reported by Thomas Åkesson.
SHA-512 checksums are available at:
https://www.apache.org/dist/subversion/subversion-1.14.1.tar.bz2.sha512
https://www.apache.org/dist/subversion/subversion-1.14.1.tar.gz.sha512
https://www.apache.org/dist/subversion/subversion-1.14.1.zip.sha512
PGP Signatures are available at:
https://www.apache.org/dist/subversion/subversion-1.14.1.tar.bz2.asc
https://www.apache.org/dist/subversion/subversion-1.14.1.tar.gz.asc
https://www.apache.org/dist/subversion/subversion-1.14.1.zip.asc
For this release, the following people have provided PGP signatures:
Stefan Sperling [2048R/4F7DBAA99A59B973] with fingerprint:
8BC4 DAE0 C5A4 D65F 4044 0107 4F7D BAA9 9A59 B973
Branko Čibej [4096R/1BCA6586A347943F] with fingerprint:
BA3C 15B1 337C F0FB 222B D41A 1BCA 6586 A347 943F
Johan Corveleyn [4096R/B59CE6D6010C8AAD] with fingerprint:
8AA2 C10E EAAD 44F9 6972 7AEA B59C E6D6 010C 8AAD
These public keys are available at:
https://www.apache.org/dist/subversion/subversion-1.14.1.KEYS
Release notes for the 1.14.x release series may be found at:
https://subversion.apache.org/docs/release-notes/1.14.html
You can find the list of changes between 1.14.1 and earlier versions at:
https://svn.apache.org/repos/asf/subversion/tags/1.14.1/CHANGES
Questions, comments, and bug reports to users@subversion.apache.org.
Thanks,
- The Subversion Team
--
To unsubscribe, please see:
https://subversion.apache.org/mailing-lists.html#unsubscribing
----- End forwarded message -----