Re: [CVE-2018-11803] Apache Subversion Denial of Service Vulnerability

2019-01-24 Thread Troy Curtis Jr
On Thu, Jan 24, 2019 at 2:17 PM Julian Foad wrote: > > Thanks, Troy. > > I have noted this CVE fix in the CHANGES file in r1852014 and pushed it to > 1.10 and 1.11 branches so people looking there can find it. > Thanks Julian! That was on my TODO list, but didn't get to it last night. I also was

Re: [CVE-2018-11803] Apache Subversion Denial of Service Vulnerability

2019-01-24 Thread Julian Foad
Thanks, Troy. I have noted this CVE fix in the CHANGES file in r1852014 and pushed it to 1.10 and 1.11 branches so people looking there can find it. -- - Julian

Re: [CVE-2018-11803] Apache Subversion Denial of Service Vulnerability

2019-01-23 Thread Stefan Sperling
On Wed, Jan 23, 2019 at 07:31:40PM +, Daniel Shahaf wrote: > Thanks for all the work taking care of this, Troy! Big +1 in large friendly letters!

Re: [CVE-2018-11803] Apache Subversion Denial of Service Vulnerability

2019-01-23 Thread Daniel Shahaf
Thanks for all the work taking care of this, Troy! Troy Curtis wrote on Tue, 22 Jan 2019 22:55 -0500: > This is a security notification for Apache Subversion HTTP Servers: > > CVE-2018-11803 > Severity: Medium > Affected Versions: Apache Subversion 1.11.0, 1.10.0 to 1.10.3

[CVE-2018-11803] Apache Subversion Denial of Service Vulnerability

2019-01-22 Thread Troy Curtis
This is a security notification for Apache Subversion HTTP Servers: CVE-2018-11803 Severity: Medium Affected Versions: Apache Subversion 1.11.0, 1.10.0 to 1.10.3 Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized poi