cbcvebase.
CVE-2015-5259
published 2016-01-08

CVE-2015-5259: Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary…

PriorityP261high8.6CVSS 3.0
AVNACLPRNUINSUCLILAH
EPSS
57.04%
99.0th percentile
Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// protocol string, which triggers a heap-based buffer overflow and an out-of-bounds read.

Affected

9 ranges
VendorProductVersion rangeFixed in
apachesubversion
apachesubversion
apachesubversion
apachesubversion
apachesubversion>= 0 < 1.9.3-11.9.3-1
apachesubversion>= 0 < 1.9.3-11.9.3-1
apachesubversion>= 0 < 1.9.3-11.9.3-1
apachesubversion>= 0 < 1.9.3-11.9.3-1
debiansubversion< subversion 1.9.3-1 (bookworm)subversion 1.9.3-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability exists in the `read_string` function within `libsvn_ra_svn/marshal.c` — monitor for heap-based buffer overflow or out-of-bounds read triggered via the svn:// protocol parser in Apache Subversion 1.9.0–1.9.2.
  • Attack vector is the svn:// protocol parser; network traffic on the default SVN port (3690/tcp) carrying malformed svn:// protocol strings should be inspected for integer overflow conditions.
  • Both Subversion servers and clients are affected — detection should cover both inbound connections to svnserve and outbound client connections to malicious svn:// servers.
  • ·Only Apache Subversion 1.9.x versions before 1.9.3 are affected; 1.8.x and earlier are NOT affected per Red Hat's assessment (RHEL 5/6/7 marked 'Not affected').
  • ·The upstream advisory and patch are available at the Apache Subversion security page; the patch file referenced is CVE-2015-5259-1.9.2.patch.

CVSS provenance

nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:N/C:P/I:P/A:C
osv8.6HIGH
vendor_apache8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.