Subversion performs insufficient input validation of svndiff streams. Malicious servers could cause heap overflows in clients, and malicious clients with commit access could cause heap overflows in servers, possibly leading to arbitrary code execution in both cases. Upstream released new version to fix the problem.
subversion-1.6.4-alt1 -> sisyphus: * Tue Aug 18 2009 Dmitry V. Levin <ldv@altlinux> 1.6.4-alt1 - Updated to 1.6.4 (CVE-2009-2411; closes: #21097).
спасибо, меня резко в командировку выгнали, только до почты добрался.