Path to this page:
Subject: CVS commit: pkgsrc
From: Adam Ciarcinski
Date: 2015-12-18 18:49:06
Message id: 20151218174906.DB2F6FB88@cvs.NetBSD.org
Log Message:
Changes 1.9.3:
This release fixes two security issues:
CVE-2015-5259:
Remotely triggerable heap overflow and out-of-bounds read caused by
integer overflow in the svn:// protocol parser.
http://subversion.apache.org/security/CVE-2015-5259-advisory.txt
CVE-2015-5343:
Remotely triggerable heap overflow and out-of-bounds read in mod_dav_svn
caused by integer overflow when parsing skel-encoded request bodies.
http://subversion.apache.org/security/CVE-2015-5343-advisory.txt
Files: