PT-2015-4543 · Apache+5 · Subversion+7

Ivan Zhakov

·

Published

2015-04-02

·

Updated

2024-06-15

·

CVE-2015-0251

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Subversion versions 1.5.0 through 1.7.19 Subversion versions 1.8.0 through 1.8.11
Description The issue allows remote authenticated users to spoof the svn:author property via crafted v1 HTTP protocol request sequences. This can be exploited by sending specially formed request sequences to the mod dav svn server.
Recommendations For Subversion versions 1.5.0 through 1.7.19, update to a version outside of this range to resolve the issue. For Subversion versions 1.8.0 through 1.8.11, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the mod dav svn server until a patch is available.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1708
CESA-2015_1633
CESA-2015_1742
CVE-2015-0251
DLA-207-1
DSA-3231-1
MGASA-2015-0177
OPENSUSE-SU-2024:10538-1
RHSA-2015:1633
RHSA-2015:1742
RHSA-2015_1633
RHSA-2015_1742
SUSE-SU-2015:0709-1
SUSE-SU-2015:0776-1
SUSE-SU-2017:2200-1
USN-2721-1

Affected Products

Alt Linux
Apache Subversion
Centos
Red Hat
Subversion
Suse
Ubuntu
Mod Dav Svn