CVE-2014-3528
published 2014-08-19CVE-2014-3528: Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials…
PriorityP428medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
7.50%
93.8th percentile
Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.
Affected
111 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
osv4.3MEDIUM
vendor_ubuntu4.3MEDIUM
vendor_apache4.0MEDIUM
vendor_debian4.0LOW
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2014-08-14·CVSS 4.3
CVE-2014-0032 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in Subversion.
Lieven Govaerts discovered that the Subversion mod_dav_svn module
incorrectly handled certain request methods when SVNListParentPath was
enabled. A remote attacker could use this issue to cause the server to
crash, resulting in a denial of service. This issue only affected Ubuntu
12.04 LTS. (CVE-2014-0032)
Ben Reser discovered that Subversion did not correctly validate SSL
certificates containing wildcards. A remote attacker could exploit this to
perform a machine-in-the-middle attack to view sensitive information or alter
encrypted communications. (CVE-2014-3522)
Bert Huijben discovered that Subversion did not properly handle cached
credentials. A malicious server could possibly use this issue
Debian
CVE-2014-3528: subversion - Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses...
vendor_debian·2014·CVSS 4.0
CVE-2014-3528 [MEDIUM] CVE-2014-3528: subversion - Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses...
Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.
Scope: local
bookworm: resolved (fixed in 1.8.10-1)
bullseye: resolved (fixed in 1.8.10-1)
forky: resolved (fixed in 1.8.10-1)
sid: resolved (fixed in 1.8.10-1)
trixie: resolved (fixed in 1.8.10-1)
Red Hat
subversion: credentials leak via MD5 collision
vendor_redhat·2013-12-13·CVSS 4.0
CVE-2014-3528 [MEDIUM] CWE-327 subversion: credentials leak via MD5 collision
subversion: credentials leak via MD5 collision
Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.
It was discovered that Subversion clients retrieved cached authentication credentials using the MD5 hash of the server realm string without also checking the server's URL. A malicious server able to provide a realm that triggers an MD5 collision could possibly use this flaw to obtain the credentials for a different realm.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact
Apple
CVE-2014-3528: Xcode 6.2
vendor_apple·CVSS 4.0
CVE-2014-3528 [MEDIUM] CVE-2014-3528: Xcode 6.2
Apple Security Update: About the security content of Xcode 6.2
Product: Xcode
Version: 6.2
CVE: CVE-2014-3528
Component: CVE-2014-3528
Apache
Apache subversion: CVE-2014-3528
vendor_apache·CVSS 4.0
CVE-2014-3528 [MEDIUM] Apache subversion: CVE-2014-3528
Apache subversion: CVE-2014-3528
-advisory.txt 1.0.0-1.7.17 and 1.8.0-1.8.9 credentials cached with svn may be sent to wrong server
GHSA
GHSA-vxf6-xw9g-6cfc: Apache Subversion 1
ghsa_unreviewed·2022-05-14
CVE-2014-3528 [MEDIUM] GHSA-vxf6-xw9g-6cfc: Apache Subversion 1
Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.
OSV
CVE-2014-3528: Apache Subversion 1
osv·2014-08-19·CVSS 4.0
CVE-2014-3528 [MEDIUM] CVE-2014-3528: Apache Subversion 1
Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.
OSV
subversion vulnerabilities
osv·2014-08-14·CVSS 4.3
CVE-2014-0032 [MEDIUM] subversion vulnerabilities
subversion vulnerabilities
Lieven Govaerts discovered that the Subversion mod_dav_svn module
incorrectly handled certain request methods when SVNListParentPath was
enabled. A remote attacker could use this issue to cause the server to
crash, resulting in a denial of service. This issue only affected Ubuntu
12.04 LTS. (CVE-2014-0032)
Ben Reser discovered that Subversion did not correctly validate SSL
certificates containing wildcards. A remote attacker could exploit this to
perform a machine-in-the-middle attack to view sensitive information or alter
encrypted communications. (CVE-2014-3522)
Bert Huijben discovered that Subversion did not properly handle cached
credentials. A malicious server could possibly use this issue to obtain
credentials cached for a different server. (CVE-2014-352
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2015/Mar/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2014-08/msg00038.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0165.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0166.htmlhttp://secunia.com/advisories/59432http://secunia.com/advisories/59584http://secunia.com/advisories/60722http://subversion.apache.org/security/CVE-2014-3528-advisory.txthttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.securityfocus.com/bid/68995http://www.ubuntu.com/usn/USN-2316-1https://security.gentoo.org/glsa/201610-05https://support.apple.com/HT204427http://lists.apple.com/archives/security-announce/2015/Mar/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2014-08/msg00038.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0165.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0166.htmlhttp://secunia.com/advisories/59432http://secunia.com/advisories/59584http://secunia.com/advisories/60722http://subversion.apache.org/security/CVE-2014-3528-advisory.txthttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.securityfocus.com/bid/68995http://www.ubuntu.com/usn/USN-2316-1https://security.gentoo.org/glsa/201610-05https://support.apple.com/HT204427
2014-08-19
Published