CVE-2015-0251
published 2015-04-08CVE-2015-0251: The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a…
PriorityP426medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
7.51%
93.8th percentile
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.
Affected
81 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv5.0MEDIUM
vendor_ubuntu5.0MEDIUM
vendor_apache4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2015-08-20·CVSS 5.0
CVE-2014-3580 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in Subversion.
It was discovered that the Subversion mod_dav_svn module incorrectly
handled REPORT requests for a resource that does not exist. A remote
attacker could use this issue to cause the server to crash, resulting in a
denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2014-3580)
It was discovered that the Subversion mod_dav_svn module incorrectly
handled requests requiring a lookup for a virtual transaction name that
does not exist. A remote attacker could use this issue to cause the server
to crash, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS. (CVE-2014-8108)
Evgeny Kotkov discovered that the Subversion mod_dav_svn module incorrec
Red Hat
subversion: (mod_dav_svn) spoofing svn:author property values for new revisions
vendor_redhat·2015-03-31·CVSS 4.0
CVE-2015-0251 [MEDIUM] CWE-348 subversion: (mod_dav_svn) spoofing svn:author property values for new revisions
subversion: (mod_dav_svn) spoofing svn:author property values for new revisions
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.
It was found that the mod_dav_svn module did not properly validate the svn:author property of certain requests. An attacker able to create new revisions could use this flaw to spoof the svn:author property.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://
Debian
CVE-2015-0251: subversion - The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8....
vendor_debian·2015·CVSS 4.0
CVE-2015-0251 [MEDIUM] CVE-2015-0251: subversion - The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8....
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.
Scope: local
bookworm: resolved (fixed in 1.8.10-6)
bullseye: resolved (fixed in 1.8.10-6)
forky: resolved (fixed in 1.8.10-6)
sid: resolved (fixed in 1.8.10-6)
trixie: resolved (fixed in 1.8.10-6)
Apple
CVE-2015-0251: Xcode 7.0
vendor_apple·CVSS 4.0
CVE-2015-0251 [MEDIUM] CVE-2015-0251: Xcode 7.0
Apple Security Update: About the security content of Xcode 7.0
Product: Xcode
Version: 7.0
CVE: CVE-2015-0251
Component: CVE-2015-0251
Apache
Apache subversion: CVE-2015-0251
vendor_apache·CVSS 4.0
CVE-2015-0251 [MEDIUM] Apache subversion: CVE-2015-0251
Apache subversion: CVE-2015-0251
-advisory.txt 1.5.0-1.7.19 and 1.8.0-1.8.11 Subversion HTTP servers allow spoofing svn:author property values for new revisions
GHSA
GHSA-7c78-p7xr-4r2p: The mod_dav_svn server in Subversion 1
ghsa_unreviewed·2022-05-14
CVE-2015-0251 [MEDIUM] CWE-345 GHSA-7c78-p7xr-4r2p: The mod_dav_svn server in Subversion 1
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.
OSV
subversion vulnerabilities
osv·2015-08-20·CVSS 5.0
CVE-2014-3580 [MEDIUM] subversion vulnerabilities
subversion vulnerabilities
It was discovered that the Subversion mod_dav_svn module incorrectly
handled REPORT requests for a resource that does not exist. A remote
attacker could use this issue to cause the server to crash, resulting in a
denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2014-3580)
It was discovered that the Subversion mod_dav_svn module incorrectly
handled requests requiring a lookup for a virtual transaction name that
does not exist. A remote attacker could use this issue to cause the server
to crash, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS. (CVE-2014-8108)
Evgeny Kotkov discovered that the Subversion mod_dav_svn module incorrectly
handled large numbers of REPORT requests. A remote attacker cou
OSV
CVE-2015-0251: The mod_dav_svn server in Subversion 1
osv·2015-04-08·CVSS 4.0
CVE-2015-0251 [MEDIUM] CVE-2015-0251: The mod_dav_svn server in Subversion 1
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-0251 subversion: (mod_dav_svn) spoofing svn:author property values for new revisions [fedora-all]
bugzilla·2015-03-31·CVSS 4.0
CVE-2015-0251 [MEDIUM] CVE-2015-0251 subversion: (mod_dav_svn) spoofing svn:author property values for new revisions [fedora-all]
CVE-2015-0251 subversion: (mod_dav_svn) spoofing svn:author property values for new revisions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mu
Bugzilla
CVE-2015-0251 subversion: (mod_dav_svn) spoofing svn:author property values for new revisions
bugzilla·2015-03-24·CVSS 4.0
CVE-2015-0251 [MEDIUM] CVE-2015-0251 subversion: (mod_dav_svn) spoofing svn:author property values for new revisions
CVE-2015-0251 subversion: (mod_dav_svn) spoofing svn:author property values for new revisions
Summary:
Subversion's mod_dav_svn server allows setting arbitrary svn:author
property values when committing new revisions. This can be accomplished
using a specially crafted sequence of requests. An evil-doer can fake
svn:author values on his commits. However, as authorization rules are
applied to the evil-doer's true username, forged svn:author values can
only happen on commits that touch the paths the evil-doer has write
access to.
Doing so does not grant any additional access and does not circumvent the
standard Apache authentication or authorization mechanisms. Still, an
ability to spoof svn:author property values can impact data integrity in
environments that rely on these values.
There
http://lists.apple.com/archives/security-announce/2015/Sep/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00008.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1633.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1742.htmlhttp://seclists.org/fulldisclosure/2015/Jun/32http://subversion.apache.org/security/CVE-2015-0251-advisory.txthttp://www.debian.org/security/2015/dsa-3231http://www.mandriva.com/security/advisories?name=MDVSA-2015:192http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.securityfocus.com/bid/74259http://www.securitytracker.com/id/1033214http://www.ubuntu.com/usn/USN-2721-1https://security.gentoo.org/glsa/201610-05https://support.apple.com/HT205217http://lists.apple.com/archives/security-announce/2015/Sep/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00008.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1633.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1742.htmlhttp://seclists.org/fulldisclosure/2015/Jun/32http://subversion.apache.org/security/CVE-2015-0251-advisory.txthttp://www.debian.org/security/2015/dsa-3231http://www.mandriva.com/security/advisories?name=MDVSA-2015:192http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.securityfocus.com/bid/74259http://www.securitytracker.com/id/1033214http://www.ubuntu.com/usn/USN-2721-1https://security.gentoo.org/glsa/201610-05https://support.apple.com/HT205217
2015-04-08
Published