Is 3242 actually included in this? The release notes show:

* permissions fixes when doing reintegrate merges (related to issue #3242)

but doesn't actually list "Subversion demands unnecessary access to parent 
directories of operations" in the list. (#3242) The tracker shows 1.6.13 was 
the "target milestone".

BOb


> -----Original Message-----
> From: hy...@hyrumwright.org [mailto:hy...@hyrumwright.org] On
> Behalf Of Hyrum K. Wright
> Sent: Friday, October 01, 2010 1:08 PM
> To: Subversion Development; users; announce
> Subject: Subversion 1.6.13 Released
> 
> [ Please note: I prior version of this mail referred to the
> incorrect
> CVE number. ]
> 
> I'm happy to announce Subversion 1.6.13, available from:
> 
>     http://subversion.tigris.org/downloads/subversion-
> 1.6.13.tar.bz2
>     http://subversion.tigris.org/downloads/subversion-1.6.13.tar.gz
>     http://subversion.tigris.org/downloads/subversion-1.6.13.zip
>     http://subversion.tigris.org/downloads/subversion-deps-
> 1.6.13.tar.bz2
>     http://subversion.tigris.org/downloads/subversion-deps-
> 1.6.13.tar.gz
>     http://subversion.tigris.org/downloads/subversion-deps-
> 1.6.13.zip
> 
> This is a bugfix release, part of the 1.6.x release series.  Of
> note, this
> release includes a fix which addresses CVE-2010-3315, a security
> issue when
> using 'SVNPathAuthz short_circuit'.  More information can be found
> here:
> http://subversion.apache.org/security/CVE-2010-3315-advisory.txt
> 
> The MD5 checksums are:
> 
>     7ae1c827689f21cf975804005be30aeb  subversion-1.6.13.tar.bz2
>     8451f5d771edc0a0302bd9a52d54e150  subversion-1.6.13.tar.gz
>     dd4009b239a5354b434e5f66cddde145  subversion-1.6.13.zip
>     2a7d662bac872c61a5e11c89263d7f07  subversion-deps-
> 1.6.13.tar.bz2
>     688bdb107731f9db2f3b6297b663a68d  subversion-deps-1.6.13.tar.gz
>     bb960d37f835e5e556e23e4eb85a9b08  subversion-deps-1.6.13.zip
> 
> The SHA1 checksums are:
> 
>     185efd129c3c4b04f1544d62bb9a3fcd0f58ba29  subversion-
> 1.6.13.tar.bz2
>     06d3afc49182c80ea712c13409c008d27a4e889b  subversion-
> 1.6.13.tar.gz
>     6530528fae0335cd8495ebf1f2072e2dd9df2e31  subversion-1.6.13.zip
>     e51bffda416a3a9abe068aab6f90d174dedef352  subversion-deps-
> 1.6.13.tar.bz2
>     1faa5ba0c87210f534ed445d061e4955396524d4  subversion-deps-
> 1.6.13.tar.gz
>     945ef9f68998aedf320af50d220e47a470684a06  subversion-deps-
> 1.6.13.zip
> 
> PGP Signatures are available at:
> 
>     http://subversion.tigris.org/downloads/subversion-
> 1.6.13.tar.bz2.asc
>     http://subversion.tigris.org/downloads/subversion-
> 1.6.13.tar.gz.asc
>     http://subversion.tigris.org/downloads/subversion-
> 1.6.13.zip.asc
>     http://subversion.tigris.org/downloads/subversion-deps-
> 1.6.13.tar.bz2.asc
>     http://subversion.tigris.org/downloads/subversion-deps-
> 1.6.13.tar.gz.asc
>     http://subversion.tigris.org/downloads/subversion-deps-
> 1.6.13.zip.asc
> 
> For this release, the following people have provided PGP
> signatures:
> 
>    Senthil Kumaran S [1024D/6CCD4038] with fingerprint:
>     8035 16A5 1D6E 50E2 1ECD  DE56 F68D 46FB 6CCD 4038
>    Philip Martin [2048R/ED1A599C] with fingerprint:
>     A844 790F B574 3606 EE95  9207 76D7 88E1 ED1A 599C
>    Paul T. Burba [1024D/53FCDC55] with fingerprint:
>     E630 CF54 792C F913 B13C  32C5 D916 8930 53FC DC55
>    Julian Foad [1024D/353E25BC] with fingerprint:
>     6604 5A4B 43BC F994 7777  5728 351F 33E4 353E 25BC
>    Bert Huijben [1024D/9821F7B2] with fingerprint:
>     2017 F51A 2572 0E78 8827  5329 FCFD 6305 9821 F7B2
>    Hyrum K. Wright [1024D/4E24517C] with fingerprint:
>     3324 80DA 0F8C A37D AEE6  D084 0B03 AE6E 4E24 517C
>    Stefan Sperling [1024D/F59D25F0] with fingerprint:
>     B1CF 1060 A1E9 34D1 9E86  D6D6 E5D3 0273 F59D 25F0
>    Mark Phippard [1024D/035A96A9] with fingerprint:
>     D315 89DB E1C1 E9BA D218  39FD 265D F8A0 035A 96A9
> 
> Release notes for the 1.6.x release series may be found at:
> 
>     http://subversion.apache.org/docs/release-notes/1.6.html
> 
> You can find the list of changes between 1.6.13 and earlier
> versions at:
> 
>     http://svn.apache.org/repos/asf/subversion/tags/1.6.13/CHANGES
> 
> Questions, comments, and bug reports to
> us...@subversion.apache.org.
> 
> Thanks,
> - The Subversion Team

Reply via email to