CVE-2014-3522
published 2014-08-19CVE-2014-3522: The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or…
PriorityP423medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
5.58%
92.1th percentile
The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
Affected
80 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
osv4.3MEDIUM
vendor_ubuntu4.3MEDIUM
vendor_apache4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2014-08-14·CVSS 4.3
CVE-2014-0032 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in Subversion.
Lieven Govaerts discovered that the Subversion mod_dav_svn module
incorrectly handled certain request methods when SVNListParentPath was
enabled. A remote attacker could use this issue to cause the server to
crash, resulting in a denial of service. This issue only affected Ubuntu
12.04 LTS. (CVE-2014-0032)
Ben Reser discovered that Subversion did not correctly validate SSL
certificates containing wildcards. A remote attacker could exploit this to
perform a machine-in-the-middle attack to view sensitive information or alter
encrypted communications. (CVE-2014-3522)
Bert Huijben discovered that Subversion did not properly handle cached
credentials. A malicious server could possibly use this issue
Red Hat
subversion: incorrect SSL certificate validation in Serf RA (repository access) layer
vendor_redhat·2014-08-11·CVSS 4.0
CVE-2014-3522 [MEDIUM] CWE-295 subversion: incorrect SSL certificate validation in Serf RA (repository access) layer
subversion: incorrect SSL certificate validation in Serf RA (repository access) layer
The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
Statement: Not vulnerable. This issue did not the versions of subversion as shipped with Red Hat Enterprise Linux 5, 6, and 7, as they do not use the Serf RA layer.
Package: subversion (Red Hat Enterprise Linux 5) - Not affected
Package: subversion (Red Hat Enterprise Linux 6) - Not affected
Package: subversion (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2014-3522: subversion - The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8...
vendor_debian·2014·CVSS 4.0
CVE-2014-3522 [MEDIUM] CVE-2014-3522: subversion - The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8...
The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
Scope: local
bookworm: resolved (fixed in 1.8.10-1)
bullseye: resolved (fixed in 1.8.10-1)
forky: resolved (fixed in 1.8.10-1)
sid: resolved (fixed in 1.8.10-1)
trixie: resolved (fixed in 1.8.10-1)
Apple
CVE-2014-3522: Xcode 6.2
vendor_apple·CVSS 4.0
CVE-2014-3522 [MEDIUM] CVE-2014-3522: Xcode 6.2
Apple Security Update: About the security content of Xcode 6.2
Product: Xcode
Version: 6.2
CVE: CVE-2014-3522
Component: CVE-2014-3522
Apache
Apache subversion: CVE-2014-3522
vendor_apache·CVSS 4.0
CVE-2014-3522 [MEDIUM] Apache subversion: CVE-2014-3522
Apache subversion: CVE-2014-3522
-advisory.txt 1.4.0-1.7.17 and 1.8.0-1.8.9 ra_serf improper validation of wildcards in SSL certs
GHSA
GHSA-962w-gj84-vpr7: The Serf RA layer in Apache Subversion 1
ghsa_unreviewed·2022-05-14
CVE-2014-3522 [MEDIUM] CWE-297 GHSA-962w-gj84-vpr7: The Serf RA layer in Apache Subversion 1
The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
OSV
CVE-2014-3522: The Serf RA layer in Apache Subversion 1
osv·2014-08-19·CVSS 4.0
CVE-2014-3522 [MEDIUM] CVE-2014-3522: The Serf RA layer in Apache Subversion 1
The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
OSV
subversion vulnerabilities
osv·2014-08-14·CVSS 4.3
CVE-2014-0032 [MEDIUM] subversion vulnerabilities
subversion vulnerabilities
Lieven Govaerts discovered that the Subversion mod_dav_svn module
incorrectly handled certain request methods when SVNListParentPath was
enabled. A remote attacker could use this issue to cause the server to
crash, resulting in a denial of service. This issue only affected Ubuntu
12.04 LTS. (CVE-2014-0032)
Ben Reser discovered that Subversion did not correctly validate SSL
certificates containing wildcards. A remote attacker could exploit this to
perform a machine-in-the-middle attack to view sensitive information or alter
encrypted communications. (CVE-2014-3522)
Bert Huijben discovered that Subversion did not properly handle cached
credentials. A malicious server could possibly use this issue to obtain
credentials cached for a different server. (CVE-2014-352
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3522 subversion: incorrect SSL certificate validation in Serf RA (repository access) layer [fedora-all]
bugzilla·2014-08-11·CVSS 4.0
CVE-2014-3522 [MEDIUM] CVE-2014-3522 subversion: incorrect SSL certificate validation in Serf RA (repository access) layer [fedora-all]
CVE-2014-3522 subversion: incorrect SSL certificate validation in Serf RA (repository access) layer [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2014-3522 subversion: incorrect SSL certificate validation in Serf RA (repository access) layer
bugzilla·2014-08-06·CVSS 4.0
CVE-2014-3522 [MEDIUM] CVE-2014-3522 subversion: incorrect SSL certificate validation in Serf RA (repository access) layer
CVE-2014-3522 subversion: incorrect SSL certificate validation in Serf RA (repository access) layer
It was reported that Subversion's Serf RA layer did not correctly validate SSL certificates containing wildcards. A certificate that falls within the wildcard range would be accepted as a valid, possibly leading to man-in-the-middle attacks.
This issue only affected Subversion clients that use Serf. Neon, which is used by Subversion clients in Red Hat Enterprise Linux 5, 6, and 7, is not affected.
Discussion:
Created attachment 924402
Upstream advisory draft
---
Created attachment 924403
Patch against subversion 1.7.17
---
Created attachment 924404
Patch against subversion 1.8.9
---
Note that the above patches introduce one other unrelated change - if any Subject Alternate Name is
http://lists.apple.com/archives/security-announce/2015/Mar/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2014-08/msg00038.htmlhttp://secunia.com/advisories/59432http://secunia.com/advisories/59584http://secunia.com/advisories/60100http://secunia.com/advisories/60722http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.osvdb.org/109996http://www.securityfocus.com/bid/69237http://www.ubuntu.com/usn/USN-2316-1https://exchange.xforce.ibmcloud.com/vulnerabilities/95090https://exchange.xforce.ibmcloud.com/vulnerabilities/95311https://security.gentoo.org/glsa/201610-05https://subversion.apache.org/security/CVE-2014-3522-advisory.txthttps://support.apple.com/HT204427http://lists.apple.com/archives/security-announce/2015/Mar/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2014-08/msg00038.htmlhttp://secunia.com/advisories/59432http://secunia.com/advisories/59584http://secunia.com/advisories/60100http://secunia.com/advisories/60722http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.osvdb.org/109996http://www.securityfocus.com/bid/69237http://www.ubuntu.com/usn/USN-2316-1https://exchange.xforce.ibmcloud.com/vulnerabilities/95090https://exchange.xforce.ibmcloud.com/vulnerabilities/95311https://security.gentoo.org/glsa/201610-05https://subversion.apache.org/security/CVE-2014-3522-advisory.txthttps://support.apple.com/HT204427
2014-08-19
Published