網(wǎng)路冷眼@BlogJava

          熙熙攘攘一閑人 以冷靜的眼光觀察技術(shù)
          posts - 88, comments - 193, trackbacks - 0, articles - 28
            BlogJava :: 首頁 :: 新隨筆 :: 聯(lián)系 :: 聚合  :: 管理

          Subversion 1.4.5 Released

          August 27, 2007

          Subversion 1.4.5 was released today.  You can download the updated CollabNet Subversion binaries immediately.

          Subversion 1.4.5 contains a fix for a security exploit on Windows clients. This exploit was discovered and reported by researchers at the Colorado Research Institute for Security and Privacy.

          The only change from Subversion 1.4.4 is the patch for this security exploit.  Since the exploit only affects Windows clients, we decided to only release CollabNet Subversion 1.4.5 packages for Windows. There is no point for someone who is already running 1.4.4 on any other operating system to update to 1.4.5.

          I am not going to give a lot of details about the exploit, you can find more information at various security reporting sites, such as CVE.  I will say that it was a legitimate exposure that made it possible for the Subversion client to write files outside the normal working copy.  That being said, there are a couple of points to make:

          1. Creating the exploit requires commit access to the repository.  If you can trust the people who have write access to the repository, then you do not have too much to be concerned about. The keyword in that sentence is "trust". If you are checking out from a repository you cannot completely trust, such as on a public hosting service, then be careful and update to 1.4.5 first.
          2. While the exploit itself is pretty easy to produce, it is also pretty difficult to use it in a way that would cause harm.
          3. You can only create the exploit from a non-Windows platform.
          4. There is nothing terribly secretive about the exploit.  If you send commit emails, or even just browse your repository using svn ls, this exploit would stand out as not normal.

          If you are running a Subversion client on Windows, this would include the command line client as well as any graphical client such as TortoiseSVN or Subclipse, then you should definitely go ahead and install this version of Subversion.  I would recommend that users of earlier versions such as 1.3.2 or 1.2.3 also install this update immediately. The Subversion 1.4.5 client can talk to any 1.x version of the server, so there is no reason not to update your client (for compatibility: if you have the command line and a GUI client, update them both).

          Subversion servers are not affected by this exploit.  That being said, a Windows server that uses the Subversion client in scripts would still be vulnerable and should be updated to 1.4.5.

          http://blogs.open.collab.net/svn/2007/08/subversion-145-.html


          只有注冊(cè)用戶登錄后才能發(fā)表評(píng)論。


          網(wǎng)站導(dǎo)航:
          博客園   IT新聞   Chat2DB   C++博客   博問  
           
          主站蜘蛛池模板: 曲沃县| 冀州市| 岚皋县| 略阳县| 泗水县| 长宁县| 锡林郭勒盟| 来宾市| 永善县| 通化市| 阿拉善右旗| 鲁山县| 襄樊市| 突泉县| 九龙城区| 融水| 德昌县| 梨树县| 福泉市| 桂阳县| 新乐市| 梁山县| 开江县| 赣榆县| 兴仁县| 苏尼特左旗| 遂宁市| 铁岭县| 乐山市| 玛纳斯县| 江阴市| 望城县| 九寨沟县| 富蕴县| 呼图壁县| 景谷| 临泽县| 沅陵县| 闽侯县| 三明市| 石楼县|