I have 'svnsync' failing with the following message: svnsync: Got unexpected element svn::open_directory The next revision to commit has a lot of property changes. A google turned up the following threads, pointing to a problem with dev-libs/apr-util http://subversion.tigris.org/ds/viewMessage.do?dsForumId=462&viewType=browseAll&dsMessageId=1897250 http://subversion.tigris.org/ds/viewMessage.do?dsForumId=462&viewType=browseAll&dsMessageId=1745697 The folks at CollabNet committed the following to the 'apr' trunk: http://svn.apache.org/viewvc/apr/apr/trunk/buckets/apr_brigade.c?r1=768417&r2=768416&pathrev=768417 Installing 'dev-libs/apr-util-1.3.4' with a patch for the above changeset and 'rc-config restart apache2' fixes the problem for me. Reproducible: Always
Created attachment 190333 [details, diff] Patch to remove an unnessary null terminator that causes a buffer overflow. Here is the patch I applied locally. It's the same as the following commit to the apr trunk: http://svn.apache.org/viewvc/apr/apr/trunk/buckets/apr_brigade.c?r1=768417&r2=768416&pathrev=768417
dev-libs/apr-1.3.5 was released on 2009-06-05. dev-libs/apr-util-1.3.7 was released on 2009-06-05.
====================================================== Name: CVE-2009-1956 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1956 Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
dev-libs/apr-1.3.5 and dev-libs/apr-util-1.3.7 are now in the tree.
GLSA together with bug 272260.
GLSA 200907-03