PT-2015-3232 · Apache+2 · Apache Subversion+2
Ivan Zhakov
·
Published
2015-12-15
·
Updated
2024-06-15
·
CVE-2015-5343
CVSS v2.0
8.0
High
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Apache Subversion versions 1.7.x through 1.8.14
Apache Subversion versions 1.9.x through 1.9.2
Description
The issue is caused by an integer overflow in mod dav svn, a component of the centralized version control system Apache Subversion. This can be exploited by a remote attacker to cause a denial of service, such as a server crash or memory consumption, and potentially execute arbitrary code. The exploitation is possible via a specially crafted request body, which triggers an out-of-bounds read and heap-based buffer overflow.
Recommendations
For Apache Subversion versions 1.7.x through 1.8.14, update to version 1.8.15 or later.
For Apache Subversion versions 1.9.x through 1.9.2, update to version 1.9.3 or later.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Apache Subversion
Suse