Apple Security Advisory 2014-09-17-7 - Xcode 6.0.1 is now available and addresses a denial of service vulnerability.
8e1f1756e81af7fac9dd82869a3eaffd631cf609ecd86c1fa4f32b476b409e2a
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
APPLE-SA-2014-09-17-7 Xcode 6.0.1
Xcode 6.0.1 is now available and addresses the following:
subversion
Available for: OS X Mavericks v10.9.4 or later
Impact: A malicious attacker may be able to cause Subversion
to terminate unexpectedly
Description: A denial of service issue existed in Subversion when
SVNListParentPath was enabled. This issue was addressed by updating
Subversion to version 1.7.17.
CVE-ID
CVE-2014-0032
Xcode 6.0.1 may be obtained from the Downloads section of the
Apple Developer Connection Member site: http://developer.apple.com/
Login is required, and membership is free.
Xcode 6.0.1 is also available from the App Store. It is free to
anyone with OS X Mavericks v10.9.4 and later.
To check that the Xcode has been updated:
* Select Xcode in the menu bar
* Select About Xcode
* The version after applying this update will be "6.0.1".
Information will also be posted to the Apple Security Updates
web site: http://support.apple.com/kb/HT1222
This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.22 (Darwin)
Comment: GPGTools - http://gpgtools.org
iQIcBAEBAgAGBQJUGvwLAAoJEBcWfLTuOo7tDiEP/1Tac1/EMN3gRqhAD0CyB9jJ
58rGOIkykANzfx1UItvZBb88oDy+EGhK9ZtFSyFFdC8wxq1M1UeDayYC2IoLlYQ1
dJLYZwX1FEcgZKRKMzJQRV1GusXCGLSHG+w0iol2DdCIWbNfSt5aaqwSyJBuuklD
hlIToL3rCDpHQmhfU/D2MSK56xWxExfDofYV3DNn9eETP5TnB6RFQJYxbEMpQ6DC
Gkgm6BvnF5091XNLRJ+KYTdYbCfaY1X7TUg5uBDN8xC6ygNVKw14n/wZGpbTPT+P
asyKLEVxpwvpI5QqBD6kEJlf5ALFAv5AehpCoheM40N/AOYhQ4lBL+yhHjlXmMeH
J5Ir8nWrfGTiw2e4V7+t79RZrHQq+1jutxwWRSsEh28kBJbVYSXP2ALNfjePoNLO
58tqyN5BAVi3LIPh8Zo270iIyCggHNnWN3SZlOgtKeyZV0xi7MGHTyQPoWu0nyIx
Irh7tZx514bUg8geNSljQGOReNf4R2d1nm6/gyPhd0ZP+FWfKmUmaouS6rNNW8la
igWLkDwa/iel5ILvqXXG9ZfgjGoO9sqls1ED4lV2ETLTSIgG/+2x6tfT4xfw5a6t
UiM9yByWnVrZ51DWshIfxGxcv+Gv2ciW/u/AYH3GVtSc20RXrC0vzBIbpO6BbpSS
LZkBJnMwAJAPIG/Dq385
=/vKz
-----END PGP SIGNATURE-----