CVE-2015-5259
published 2016-01-08CVE-2015-5259: Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary…
PriorityP261high8.6CVSS 3.0
AVNACLPRNUINSUCLILAH
EPSS
57.04%
99.0th percentile
Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// protocol string, which triggers a heap-based buffer overflow and an out-of-bounds read.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.9.3-1 | 1.9.3-1 |
| apache | subversion | >= 0 < 1.9.3-1 | 1.9.3-1 |
| apache | subversion | >= 0 < 1.9.3-1 | 1.9.3-1 |
| apache | subversion | >= 0 < 1.9.3-1 | 1.9.3-1 |
| debian | subversion | < subversion 1.9.3-1 (bookworm) | subversion 1.9.3-1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability exists in the `read_string` function within `libsvn_ra_svn/marshal.c` — monitor for heap-based buffer overflow or out-of-bounds read triggered via the svn:// protocol parser in Apache Subversion 1.9.0–1.9.2. ↗
- →Attack vector is the svn:// protocol parser; network traffic on the default SVN port (3690/tcp) carrying malformed svn:// protocol strings should be inspected for integer overflow conditions. ↗
- →Both Subversion servers and clients are affected — detection should cover both inbound connections to svnserve and outbound client connections to malicious svn:// servers. ↗
- ·Only Apache Subversion 1.9.x versions before 1.9.3 are affected; 1.8.x and earlier are NOT affected per Red Hat's assessment (RHEL 5/6/7 marked 'Not affected'). ↗
- ·The upstream advisory and patch are available at the Apache Subversion security page; the patch file referenced is CVE-2015-5259-1.9.2.patch. ↗
CVSS provenance
nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:N/C:P/I:P/A:C
osv8.6HIGH
vendor_apache8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
subversion: integer overflow in the svn:// protocol parser
vendor_redhat·2015-12-15·CVSS 8.6
CVE-2015-5259 [HIGH] CWE-190 subversion: integer overflow in the svn:// protocol parser
subversion: integer overflow in the svn:// protocol parser
Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// protocol string, which triggers a heap-based buffer overflow and an out-of-bounds read.
Package: subversion (Red Hat Enterprise Linux 5) - Not affected
Package: subversion (Red Hat Enterprise Linux 6) - Not affected
Package: subversion (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2015-5259: subversion - Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apach...
vendor_debian·2015·CVSS 8.6
CVE-2015-5259 [HIGH] CVE-2015-5259: subversion - Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apach...
Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// protocol string, which triggers a heap-based buffer overflow and an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 1.9.3-1)
bullseye: resolved (fixed in 1.9.3-1)
forky: resolved (fixed in 1.9.3-1)
sid: resolved (fixed in 1.9.3-1)
trixie: resolved (fixed in 1.9.3-1)
Apache
Apache subversion: CVE-2015-5259
vendor_apache·CVSS 8.6
CVE-2015-5259 [HIGH] Apache subversion: CVE-2015-5259
Apache subversion: CVE-2015-5259
-advisory.txt 1.9.0-1.9.2 Remotely triggerable heap overflow and out-of-bounds read caused by integer overflow in the svn:// protocol parser.
GHSA
GHSA-5h66-v34j-rg64: Integer overflow in the read_string function in libsvn_ra_svn/marshal
ghsa_unreviewed·2022-05-17
CVE-2015-5259 [HIGH] CWE-119 GHSA-5h66-v34j-rg64: Integer overflow in the read_string function in libsvn_ra_svn/marshal
Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// protocol string, which triggers a heap-based buffer overflow and an out-of-bounds read.
OSV
CVE-2015-5259: Integer overflow in the read_string function in libsvn_ra_svn/marshal
osv·2016-01-08·CVSS 8.6
CVE-2015-5259 [HIGH] CVE-2015-5259: Integer overflow in the read_string function in libsvn_ra_svn/marshal
Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// protocol string, which triggers a heap-based buffer overflow and an out-of-bounds read.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5259 CVE-2015-5343 subversion: various flaws [fedora-all]
bugzilla·2015-12-16·CVSS 8.6
CVE-2015-5259 [HIGH] CVE-2015-5259 CVE-2015-5343 subversion: various flaws [fedora-all]
CVE-2015-5259 CVE-2015-5343 subversion: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
Bugzilla
CVE-2015-5259 subversion: integer overflow in the svn:// protocol parser
bugzilla·2015-12-09·CVSS 8.6
CVE-2015-5259 [HIGH] CVE-2015-5259 subversion: integer overflow in the svn:// protocol parser
CVE-2015-5259 subversion: integer overflow in the svn:// protocol parser
The following flaw was reported in Subversion:
Subversion servers and clients are vulnerable to a remotely triggerable heap-based buffer overflow and out-of-bounds read caused by an integer overflow in the svn:// protocol parser.
This allows remote attackers to cause a denial of service or possibly execute arbitrary code under the context of the targeted process.
Acknowledgements:
Red Hat would like to thank the Apache Software Foundation for reporting this issue. Upstream acknowledges Ivan Zhakov of VisualSVN as the original reporter.
Discussion:
Created attachment 1103853
CVE-2015-5259-1.9.2.patch
---
Public via upstream advisory:
External References:
https://subversion.apache.org/security/CVE-2015-5259-a
http://subversion.apache.org/security/CVE-2015-5259-advisory.txthttp://www.securityfocus.com/bid/82300http://www.securitytracker.com/id/1034469https://security.gentoo.org/glsa/201610-05http://subversion.apache.org/security/CVE-2015-5259-advisory.txthttp://www.securityfocus.com/bid/82300http://www.securitytracker.com/id/1034469https://security.gentoo.org/glsa/201610-05
2016-01-08
Published