PT-2015-3388 · Apache+5 · Subversion+6

Evgeny Kotkov

·

Published

2015-04-02

·

Updated

2024-06-15

·

CVE-2015-0248

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Subversion versions 1.6.0 through 1.7.19 Subversion versions 1.8.0 through 1.8.11
Description The issue is related to resource management errors in the mod dav svn and svnserve servers of the Subversion centralized version control system. Exploitation of this issue may allow a remote attacker to cause a denial of service when processing certain combinations of parameters related to dynamically evaluated revision numbers. This can lead to an assertion failure and abort.
Recommendations For Subversion versions 1.6.0 through 1.7.19, update to a version outside of this range to resolve the issue. For Subversion versions 1.8.0 through 1.8.11, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the mod dav svn and svnserve servers until a patch is available.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1708
BDU:2020-04532
CESA-2015_1633
CESA-2015_1742
CVE-2015-0248
DLA-207-1
DSA-3231-1
MGASA-2015-0177
OPENSUSE-SU-2024:10538-1
RHSA-2015:1633
RHSA-2015:1742
RHSA-2015_1633
RHSA-2015_1742
SUSE-SU-2015:0709-1
SUSE-SU-2015:0776-1
SUSE-SU-2015_0709-1
SUSE-SU-2017:2200-1
USN-2721-1

Affected Products

Alt Linux
Apache Subversion
Centos
Red Hat
Subversion
Suse
Ubuntu