subversion: security bump to version 1.7.18
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Fri, 15 Aug 2014 18:25:21 +0000 (15:25 -0300)
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>
Fri, 15 Aug 2014 20:29:04 +0000 (22:29 +0200)
Fixes:

CVE-2014-0032 - mod_dav_svn is vunerable to a remotely triggerable
segfault DoS vulnerability when SVNListParentPath is on.

CVE-2014-3522 - Serf RA layer does not correctly validate certificates
with wildcards in them for HTTPS.

CVE-2014-3528 - Credentials cached with Subversion may be sent to the
wrong server.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
package/subversion/subversion.mk

index d7a4b42559a6aba3fd09b384f10b30f999dae30d..e78936a6c409ab8668b28871c9411777067b3888 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-SUBVERSION_VERSION = 1.7.14
+SUBVERSION_VERSION = 1.7.18
 SUBVERSION_SITE = http://archive.apache.org/dist/subversion
 SUBVERSION_LICENSE = Apache-2.0
 SUBVERSION_LICENSE_FILES = LICENSE