CVE-2015-0202
published 2015-04-08CVE-2015-0202: The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large number of…
PriorityP339high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
8.03%
94.1th percentile
The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large number of REPORT requests, which trigger the traversal of FSFS repository nodes.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.8.10-6 | 1.8.10-6 |
| apache | subversion | >= 0 < 1.8.10-6 | 1.8.10-6 |
| apache | subversion | >= 0 < 1.8.10-6 | 1.8.10-6 |
| apache | subversion | >= 0 < 1.8.10-6 | 1.8.10-6 |
| apache | subversion | >= 0 < 1.8.8-1ubuntu3.2 | 1.8.8-1ubuntu3.2 |
| debian | subversion | < subversion 1.8.10-6 (bookworm) | subversion 1.8.10-6 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_apache7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9652-39q9-6g87: The mod_dav_svn server in Subversion 1
ghsa_unreviewed·2022-05-14
CVE-2015-0202 [HIGH] GHSA-9652-39q9-6g87: The mod_dav_svn server in Subversion 1
The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large number of REPORT requests, which trigger the traversal of FSFS repository nodes.
OSV
subversion vulnerabilities
osv·2015-08-20·CVSS 5.0
CVE-2014-3580 [MEDIUM] subversion vulnerabilities
subversion vulnerabilities
It was discovered that the Subversion mod_dav_svn module incorrectly
handled REPORT requests for a resource that does not exist. A remote
attacker could use this issue to cause the server to crash, resulting in a
denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2014-3580)
It was discovered that the Subversion mod_dav_svn module incorrectly
handled requests requiring a lookup for a virtual transaction name that
does not exist. A remote attacker could use this issue to cause the server
to crash, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS. (CVE-2014-8108)
Evgeny Kotkov discovered that the Subversion mod_dav_svn module incorrectly
handled large numbers of REPORT requests. A remote attacker cou
OSV
CVE-2015-0202: The mod_dav_svn server in Subversion 1
osv·2015-04-08·CVSS 7.8
CVE-2015-0202 [HIGH] CVE-2015-0202: The mod_dav_svn server in Subversion 1
The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large number of REPORT requests, which trigger the traversal of FSFS repository nodes.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2015-08-20·CVSS 5.0
CVE-2014-3580 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in Subversion.
It was discovered that the Subversion mod_dav_svn module incorrectly
handled REPORT requests for a resource that does not exist. A remote
attacker could use this issue to cause the server to crash, resulting in a
denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2014-3580)
It was discovered that the Subversion mod_dav_svn module incorrectly
handled requests requiring a lookup for a virtual transaction name that
does not exist. A remote attacker could use this issue to cause the server
to crash, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS. (CVE-2014-8108)
Evgeny Kotkov discovered that the Subversion mod_dav_svn module incorrec
Red Hat
subversion: (mod_dav_svn) remote denial of service with certain REPORT requests
vendor_redhat·2015-03-31·CVSS 7.8
CVE-2015-0202 [HIGH] CWE-770 subversion: (mod_dav_svn) remote denial of service with certain REPORT requests
subversion: (mod_dav_svn) remote denial of service with certain REPORT requests
The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large number of REPORT requests, which trigger the traversal of FSFS repository nodes.
Statement: Not vulnerable. This issue did not affect the versions of subversion as shipped with Red Hat Enterprise Linux 5, 6 and 7 as they did not include support for additional level of caching for the DAG nodes, which cause excessive memory use due to the cached nodes not being deallocated in a timely manner.
Package: subversion (Red Hat Enterprise Linux 5) - Not affected
Package: subversion (Red Hat Enterprise Linux 6) - Not affected
Package: subversion (Red Hat Enterprise Linux 7)
Debian
CVE-2015-0202: subversion - The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attacker...
vendor_debian·2015·CVSS 7.8
CVE-2015-0202 [HIGH] CVE-2015-0202: subversion - The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attacker...
The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large number of REPORT requests, which trigger the traversal of FSFS repository nodes.
Scope: local
bookworm: resolved (fixed in 1.8.10-6)
bullseye: resolved (fixed in 1.8.10-6)
forky: resolved (fixed in 1.8.10-6)
sid: resolved (fixed in 1.8.10-6)
trixie: resolved (fixed in 1.8.10-6)
Apache
Apache subversion: CVE-2015-0202
vendor_apache·CVSS 7.8
CVE-2015-0202 [HIGH] Apache subversion: CVE-2015-0202
Apache subversion: CVE-2015-0202
-advisory.txt 1.8.0-1.8.11 Subversion HTTP servers with FSFS repositories are vulnerable to a remotely triggerable excessive memory use with certain REPORT requests
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-0202 subversion: (mod_dav_svn) remote denial of service with certain REPORT requests [fedora-all]
bugzilla·2015-03-31·CVSS 7.8
CVE-2015-0202 [HIGH] CVE-2015-0202 subversion: (mod_dav_svn) remote denial of service with certain REPORT requests [fedora-all]
CVE-2015-0202 subversion: (mod_dav_svn) remote denial of service with certain REPORT requests [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mu
Bugzilla
CVE-2015-0202 subversion: (mod_dav_svn) remote denial of service with certain REPORT requests
bugzilla·2015-03-24·CVSS 7.8
CVE-2015-0202 [HIGH] CVE-2015-0202 subversion: (mod_dav_svn) remote denial of service with certain REPORT requests
CVE-2015-0202 subversion: (mod_dav_svn) remote denial of service with certain REPORT requests
Summary:
Subversion's mod_dav_svn Apache HTTPD server module may use excessive
amounts of memory when processing REPORT requests that require traversing
through a large number of FSFS repository nodes (files and directories).
This can lead to a DoS. There are no known instances of this problem
being observed in the wild, but an exploit has been tested.
Details:
Subversion FSFS repositories cache different types of data for performance
reasons. An FSFS repository filesystem is structured as a direct acyclic
graph (DAG), and it has a special cache for the DAG nodes. Subversion 1.8.0
added an additional level of caching for the DAG nodes, and the excessive
memory use is a consequence of the cach
http://lists.opensuse.org/opensuse-updates/2015-04/msg00008.htmlhttp://subversion.apache.org/security/CVE-2015-0202-advisory.txthttp://www.mandriva.com/security/advisories?name=MDVSA-2015:192http://www.securityfocus.com/bid/76446http://www.securitytracker.com/id/1032100http://www.ubuntu.com/usn/USN-2721-1https://security.gentoo.org/glsa/201610-05http://lists.opensuse.org/opensuse-updates/2015-04/msg00008.htmlhttp://subversion.apache.org/security/CVE-2015-0202-advisory.txthttp://www.mandriva.com/security/advisories?name=MDVSA-2015:192http://www.securityfocus.com/bid/76446http://www.securitytracker.com/id/1032100http://www.ubuntu.com/usn/USN-2721-1https://security.gentoo.org/glsa/201610-05
2015-04-08
Published