oss-sec mailing list archives

Possible CVE request: subversion MD5 collision authentication leak


From: Marcus Meissner <meissner () suse de>
Date: Fri, 1 Aug 2014 12:12:59 +0200

Hi,

The subversion list has fixed a md5 collision attack possibility.

http://mail-archives.apache.org/mod_mbox/subversion-dev/201407.mbox/%3C53DAB4A7.8030004%40reser.org%3E

http://svn.apache.org/r1550691
http://svn.apache.org/r1550772

The referenced E-Mail speaks about CVE request, so not sure who will assign
one.

Ciao, Marcus


Current thread: