PT-2015-3232 · Apache+2 · Apache Subversion+2
Ivan Zhakov
·
Publicado
2015-12-15
·
Atualizado
2024-06-15
·
CVE-2015-5343
CVSS v2.0
8.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Apache Subversion versions 1.7.x through 1.8.14
Apache Subversion versions 1.9.x through 1.9.2
Description
The issue is caused by an integer overflow in mod dav svn, a component of the centralized version control system Apache Subversion. This can be exploited by a remote attacker to cause a denial of service, such as a server crash or memory consumption, and potentially execute arbitrary code. The exploitation is possible via a specially crafted request body, which triggers an out-of-bounds read and heap-based buffer overflow.
Recommendations
For Apache Subversion versions 1.7.x through 1.8.14, update to version 1.8.15 or later.
For Apache Subversion versions 1.9.x through 1.9.2, update to version 1.9.3 or later.
Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Apache Subversion
Suse