Stefan Küng
2014-08-11 20:04:48 UTC
Hi,
TortoiseSVN 1.8.8 is ready for download.
It is linked against Subversion 1.8.10.
This is a bugfix-only release.
The svn library fixes two security issues:
CVE-2014-3522: ra_serf improper validation of wildcards in SSL certs.
CVE-2014-3528: credentials cached with svn may be sent to wrong server.
The serf library fixes one security issue:
CVE-2014-3504: serf does not correctly validate certificates
with wildcards in them for HTTPs
CVE-2014-3522 and CVE-2014-3504 are for the same issue, but have
separate CVE numbers, one for each lib.
For more info on the security issues in svn please read the full
advisories here:
http://subversion.apache.org/security/
And we're linking now with OpenSSL 1.0.1i which has also a few security
issues fixed, which you can read about here:
http://www.openssl.org/news/secadv_20140806.txt
You can get it from our download page:
http://tortoisesvn.net/downloads.html
Since it may take a while for the website changes to go live, here's the
link to the sourceforge files section:
https://sourceforge.net/projects/tortoisesvn/files/1.8.8/
Since there are security issues fixed, we've also released TortoiseSVN
1.7.15 which is available from the Sourceforge files section:
https://sourceforge.net/projects/tortoisesvn/files/1.7.15/
The changelog for TortoiseSVN 1.8.8:
Version 1.8.8
- BUG: Issue #640: Restore after commit - Unchecked
files are not restored upon commit. (Stefan)
- BUG: Issue #641: svn:global-ignores does not work
with multiple targets selected. (Stefan)
- BUG: Issue #642: Log message not saved in history
on cancel. (Stefan)
- BUG: Issue #644: Bug in rename when "similar file name"
renames are involved and file names
include multiple dots. (Stefan)
- BUG: Issue #653: Unified diff from log no longer
includes property changes. (Stefan)
Stefan
--
___
oo // \\ "De Chelonian Mobile"
(_,\/ \_/ \ TortoiseSVN
\ \_/_\_/> The coolest interface to (Sub)version control
/_/ \_\ http://tortoisesvn.net
------------------------------------------------------
http://tortoisesvn.tigris.org/ds/viewMessage.do?dsForumId=757&dsMessageId=3086615
To unsubscribe from this discussion, e-mail: [dev-***@tortoisesvn.tigris.org].
TortoiseSVN 1.8.8 is ready for download.
It is linked against Subversion 1.8.10.
This is a bugfix-only release.
The svn library fixes two security issues:
CVE-2014-3522: ra_serf improper validation of wildcards in SSL certs.
CVE-2014-3528: credentials cached with svn may be sent to wrong server.
The serf library fixes one security issue:
CVE-2014-3504: serf does not correctly validate certificates
with wildcards in them for HTTPs
CVE-2014-3522 and CVE-2014-3504 are for the same issue, but have
separate CVE numbers, one for each lib.
For more info on the security issues in svn please read the full
advisories here:
http://subversion.apache.org/security/
And we're linking now with OpenSSL 1.0.1i which has also a few security
issues fixed, which you can read about here:
http://www.openssl.org/news/secadv_20140806.txt
You can get it from our download page:
http://tortoisesvn.net/downloads.html
Since it may take a while for the website changes to go live, here's the
link to the sourceforge files section:
https://sourceforge.net/projects/tortoisesvn/files/1.8.8/
Since there are security issues fixed, we've also released TortoiseSVN
1.7.15 which is available from the Sourceforge files section:
https://sourceforge.net/projects/tortoisesvn/files/1.7.15/
The changelog for TortoiseSVN 1.8.8:
Version 1.8.8
- BUG: Issue #640: Restore after commit - Unchecked
files are not restored upon commit. (Stefan)
- BUG: Issue #641: svn:global-ignores does not work
with multiple targets selected. (Stefan)
- BUG: Issue #642: Log message not saved in history
on cancel. (Stefan)
- BUG: Issue #644: Bug in rename when "similar file name"
renames are involved and file names
include multiple dots. (Stefan)
- BUG: Issue #653: Unified diff from log no longer
includes property changes. (Stefan)
Stefan
--
___
oo // \\ "De Chelonian Mobile"
(_,\/ \_/ \ TortoiseSVN
\ \_/_\_/> The coolest interface to (Sub)version control
/_/ \_\ http://tortoisesvn.net
------------------------------------------------------
http://tortoisesvn.tigris.org/ds/viewMessage.do?dsForumId=757&dsMessageId=3086615
To unsubscribe from this discussion, e-mail: [dev-***@tortoisesvn.tigris.org].