[Bug 957727] Re: apr: update to 1.4.6 to fix svn fsfs repository corruption
lucid has seen the end of its life and is no longer receiving any updates. Marking the lucid task for this ticket as Won't Fix. ** Changed in: apr (Ubuntu Lucid) Status: New = Won't Fix -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apr in Ubuntu. https://bugs.launchpad.net/bugs/957727 Title: apr: update to 1.4.6 to fix svn fsfs repository corruption To manage notifications about this bug go to: https://bugs.launchpad.net/apr/+bug/957727/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs
[Bug 957727]
Thank you for reporting this bug to Ubuntu. oneiric has reached EOL (End of Life) and is no longer supported. As a result, this bug against oneiric is being marked Won't Fix. Please see https://wiki.ubuntu.com/Releases for currently supported Ubuntu releases. Please feel free to report any other bugs you may find. ** Changed in: apr (Ubuntu Oneiric) Status: New = Won't Fix -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apr in Ubuntu. https://bugs.launchpad.net/bugs/957727 Title: apr: update to 1.4.6 to fix svn fsfs repository corruption To manage notifications about this bug go to: https://bugs.launchpad.net/apr/+bug/957727/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs
[Bug 957727]
Thank you for reporting this bug to Ubuntu. natty has reached EOL (End of Life) and is no longer supported. As a result, this bug against natty is being marked Won't Fix. Please see https://wiki.ubuntu.com/Releases for currently supported Ubuntu releases. Please feel free to report any other bugs you may find. ** Changed in: apr (Ubuntu Natty) Status: New = Won't Fix -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apr in Ubuntu. https://bugs.launchpad.net/bugs/957727 Title: apr: update to 1.4.6 to fix svn fsfs repository corruption To manage notifications about this bug go to: https://bugs.launchpad.net/apr/+bug/957727/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs
[Bug 957727]
Thank you for reporting this bug to Ubuntu. maverick has reached EOL (End of Life) and is no longer supported. As a result, this bug against maverick is being marked Won't Fix. Please see https://wiki.ubuntu.com/Releases for currently supported Ubuntu releases. Please feel free to report any other bugs you may find. ** Changed in: apr (Ubuntu Maverick) Status: New = Won't Fix -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apr in Ubuntu. https://bugs.launchpad.net/bugs/957727 Title: apr: update to 1.4.6 to fix svn fsfs repository corruption To manage notifications about this bug go to: https://bugs.launchpad.net/apr/+bug/957727/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs
[Bug 957727] Re: apr: update to 1.4.6 to fix svn fsfs repository corruption
This bug was fixed in the package apr - 1.4.6-1 Sponsored for Blair Zajac (blair) --- apr (1.4.6-1) unstable; urgency=low * New upstream release: - Fixes apr_file_trunc() bug which could lead to subversion repository corruption. Closes: #664451 - Adds randomization to hashes. CVE-2012-0840 (but not known to be exploitable in httpd or svn). Closes: #655435 * Remove Tollef Fog Heen and Ryan Niebur from uploaders. Thanks for your work in the past. -- Stefan Fritsch s...@debian.org Sun, 18 Mar 2012 23:22:59 +0100 ** Changed in: apr (Ubuntu) Importance: Undecided = Medium ** Changed in: apr (Ubuntu) Milestone: None = ubuntu-12.04-beta-2 ** Also affects: apr (Ubuntu Precise) Importance: Medium Status: New ** Changed in: apr (Ubuntu) Status: New = Fix Released ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2012-0840 ** Also affects: apr (Ubuntu Lucid) Importance: Undecided Status: New ** Also affects: apr (Ubuntu Maverick) Importance: Undecided Status: New ** Also affects: apr (Ubuntu Oneiric) Importance: Undecided Status: New ** Also affects: apr (Ubuntu Natty) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apr in Ubuntu. https://bugs.launchpad.net/bugs/957727 Title: apr: update to 1.4.6 to fix svn fsfs repository corruption To manage notifications about this bug go to: https://bugs.launchpad.net/apr/+bug/957727/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs
[Bug 957727] Re: apr: update to 1.4.6 to fix svn fsfs repository corruption
Looking at the upstream changelog this should not need a FFe as its bugfixes only. Sync sounds sensible as soon as LP notices its landed in Debian unstable. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apr in Ubuntu. https://bugs.launchpad.net/bugs/957727 Title: apr: update to 1.4.6 to fix svn fsfs repository corruption To manage notifications about this bug go to: https://bugs.launchpad.net/apr/+bug/957727/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs
[Bug 957727] Re: apr: update to 1.4.6 to fix svn fsfs repository corruption
Debian uploaded 1.4.6 that could be synced to 12.04. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apr in Ubuntu. https://bugs.launchpad.net/bugs/957727 Title: apr: update to 1.4.6 to fix svn fsfs repository corruption To manage notifications about this bug go to: https://bugs.launchpad.net/apr/+bug/957727/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs
[Bug 957727] [NEW] apr: update to 1.4.6 to fix svn fsfs repository corruption
Public bug reported: APR releases before 1.4.6 have a faulty truncate() implementation that can cause svn fsfs repository corruption. The next release of svn 1.6.x has a workaround for the issue, see: http://svn.apache.org/viewvc?view=revisionrevision=1240892 But since svn added the workaround, APR released 1.4.6 which has the fix in it: http://www.apache.org/dist/apr/CHANGES-APR-1.4 So updating to 1.4.6 will resolve any corruption issues in svn (due to this issue). Thanks, Blair (svn committer) ProblemType: Bug DistroRelease: Ubuntu 12.04 Package: libapr1 1.4.5-1.1ubuntu2 ProcVersionSignature: Ubuntu 3.2.0-18.29-generic 3.2.9 Uname: Linux 3.2.0-18-generic x86_64 ApportVersion: 1.94.1-0ubuntu2 Architecture: amd64 Date: Sat Mar 17 00:13:46 2012 InstallationMedia: Ubuntu 12.04 LTS Precise Pangolin - Alpha amd64 (20120122) ProcEnviron: SHELL=/bin/bash TERM=xterm PATH=(custom, user) LANG=en_US.UTF-8 SourcePackage: apr UpgradeStatus: No upgrade log present (probably fresh install) ** Affects: apr (Ubuntu) Importance: Undecided Status: New ** Tags: amd64 apport-bug precise -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apr in Ubuntu. https://bugs.launchpad.net/bugs/957727 Title: apr: update to 1.4.6 to fix svn fsfs repository corruption To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/apr/+bug/957727/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs
[Bug 957727] Re: apr: update to 1.4.6 to fix svn fsfs repository corruption
-- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apr in Ubuntu. https://bugs.launchpad.net/bugs/957727 Title: apr: update to 1.4.6 to fix svn fsfs repository corruption To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/apr/+bug/957727/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs
[Bug 957727] Re: apr: update to 1.4.6 to fix svn fsfs repository corruption
Also affects oneiric and lucid. For oneiric and precise, it would be great just to update to 1.4.6 since it's ABI compatible. For lucid, one could take these two commits from apr's trunk and apply them to the 1.3.x branch. I haven't done this myself, but my hunch says it should work without much effort: http://svn.apache.org/viewvc?view=revisionrevision=1044432 http://svn.apache.org/viewvc?view=revisionrevision=100 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apr in Ubuntu. https://bugs.launchpad.net/bugs/957727 Title: apr: update to 1.4.6 to fix svn fsfs repository corruption To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/apr/+bug/957727/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs
[Bug 957727] Re: apr: update to 1.4.6 to fix svn fsfs repository corruption
I opened a bug in Debian to track the same issue: http://bugs.debian.org /cgi-bin/bugreport.cgi?bug=664451 ** Also affects: apr Importance: Undecided Status: New ** Bug watch added: Debian Bug tracker #664451 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=664451 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apr in Ubuntu. https://bugs.launchpad.net/bugs/957727 Title: apr: update to 1.4.6 to fix svn fsfs repository corruption To manage notifications about this bug go to: https://bugs.launchpad.net/apr/+bug/957727/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs