Peter Samuelson wrote:
> [Michael Biebl]
>> Today I did a svn checkout of the kdesupport svn.
>> svn died with a SEGFAULT when fetching the external reference:
> 
> Could you try 1.5.4dfsg1-1 from experimental?  It fixes at least one
> segfault with externals.  I think the experimental build uses only
> lenny Depends.  You will need 'libsvn1' and 'subversion'.

I think the backtrace led me in the correct direction, as it was
segfaulting in libgnutls. I checked when libgnutls was last updated, and
it was yesterday.
I checked the changelog:

gnutls26 (2.4.2-2) unstable; urgency=medium

  * [CVE-2008-4989.diff] Fix man in the middle attack for certificate
    verification. CVE-2008-4989 GNUTLS-SA-2008-3

 -- Andreas Metzler <[EMAIL PROTECTED]>  Mon, 10 Nov 2008 19:42:54 +0100

And indeed, this is the culprit. If I revert to version 2.4.2-1, the
crashes in subversion are gone.

I don't know the code, so I'm not sure if this is a bug in subversion or
gnutls, so If CCed Andreas, maybe he can comment on this and if this bug
should be reassigned to gnutls.

Cheers,
Michael

-- 
Why is it that all of the instruments seeking intelligent life in the
universe are pointed away from Earth?

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to