PT-2015-3232 · Apache+2 · Apache Subversion+2

Ivan Zhakov

·

Published

2015-12-15

·

Updated

2024-06-15

·

CVE-2015-5343

CVSS v2.0

8.0

High

VectorAV:N/AC:L/Au:S/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions Apache Subversion versions 1.7.x through 1.8.14 Apache Subversion versions 1.9.x through 1.9.2
Description The issue is caused by an integer overflow in mod dav svn, a component of the centralized version control system Apache Subversion. This can be exploited by a remote attacker to cause a denial of service, such as a server crash or memory consumption, and potentially execute arbitrary code. The exploitation is possible via a specially crafted request body, which triggers an out-of-bounds read and heap-based buffer overflow.
Recommendations For Apache Subversion versions 1.7.x through 1.8.14, update to version 1.8.15 or later. For Apache Subversion versions 1.9.x through 1.9.2, update to version 1.9.3 or later.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1641
ALT-PU-2020-2914
BDU:2016-01127
CVE-2015-5343
DSA-3424-1
MGASA-2015-0490
OPENSUSE-SU-2024:10538-1
SUSE-SU-2016:0043-1
SUSE-SU-2016_0043-1
SUSE-SU-2017:2200-1

Affected Products

Alt Linux
Apache Subversion
Suse