SECUNIA ADVISORY ID: SA40355
VERIFY ADVISORY: http://secunia.com/advisories/40355/
RELEASE DATE: 2010-07-01
DISCUSS ADVISORY: http://secunia.com/advisories/40355/#comments
DESCRIPTION: A vulnerability has been reported in TortoiseSVN, which can be exploited by malicious people to conduct spoofing attacks. The vulnerability is caused due to the use of a vulnerable version of the neon library.
For more information: SA36371. Note: This also fixes a Denial of Service when processing certain XML entities.
SOLUTION: Update to version 1.6.5.
PROVIDED AND/OR DISCOVERED BY: Reported by the vendor.
ORIGINAL ADVISORY: http://tortoisesvn.net/node/378
OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/products/corporate/EVM/
TortoiseSVN Spoofing VulnerabilityPosted on Saturday, July 03, 2010 @ 18:05:02 CDT in Security |