CVE-2015-5343
published 2016-04-14CVE-2015-5343: Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a…
PriorityP354high7.6CVSS 3.0
AVNACLPRLUINSUCLILAH
EPSS
30.22%
98.0th percentile
Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbitrary code via a skel-encoded request body, which triggers an out-of-bounds read and heap-based buffer overflow.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | >= 0 < 1.9.3-1 | 1.9.3-1 |
| apache | subversion | >= 0 < 1.9.3-1 | 1.9.3-1 |
| apache | subversion | >= 0 < 1.9.3-1 | 1.9.3-1 |
| apache | subversion | >= 0 < 1.9.3-1 | 1.9.3-1 |
| apache | subversion | 1.7.0 – 1.7.20 | — |
| apache | subversion | >= 1.8.0 < 1.8.15 | 1.8.15 |
| apache | subversion | >= 1.9.0 < 1.9.3 | 1.9.3 |
| debian | debian_linux | — | — |
| debian | subversion | < subversion 1.9.3-1 (bookworm) | subversion 1.9.3-1 (bookworm) |
CVSS provenance
nvdv3.07.6HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
nvdv2.08.0HIGHAV:N/AC:L/Au:S/C:P/I:P/A:C
osv7.6HIGH
vendor_debian7.6HIGH
vendor_redhat7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g5xg-c32g-4v99: Integer overflow in util
ghsa_unreviewed·2022-05-14
CVE-2015-5343 [HIGH] CWE-119 GHSA-g5xg-c32g-4v99: Integer overflow in util
Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbitrary code via a skel-encoded request body, which triggers an out-of-bounds read and heap-based buffer overflow.
OSV
CVE-2015-5343: Integer overflow in util
osv·2016-04-14·CVSS 7.6
CVE-2015-5343 [HIGH] CVE-2015-5343: Integer overflow in util
Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbitrary code via a skel-encoded request body, which triggers an out-of-bounds read and heap-based buffer overflow.
Red Hat
subversion: (mod_dav_svn) integer overflow when parsing skel-encoded request bodies
vendor_redhat·2015-12-15·CVSS 7.6
CVE-2015-5343 [HIGH] CWE-190 subversion: (mod_dav_svn) integer overflow when parsing skel-encoded request bodies
subversion: (mod_dav_svn) integer overflow when parsing skel-encoded request bodies
Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbitrary code via a skel-encoded request body, which triggers an out-of-bounds read and heap-based buffer overflow.
Package: subversion (Red Hat Enterprise Linux 5) - Not affected
Package: subversion (Red Hat Enterprise Linux 6) - Not affected
Package: subversion (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2015-5343: subversion - Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x befo...
vendor_debian·2015·CVSS 7.6
CVE-2015-5343 [HIGH] CVE-2015-5343: subversion - Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x befo...
Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbitrary code via a skel-encoded request body, which triggers an out-of-bounds read and heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.9.3-1)
bullseye: resolved (fixed in 1.9.3-1)
forky: resolved (fixed in 1.9.3-1)
sid: resolved (fixed in 1.9.3-1)
trixie: resolved (fixed in 1.9.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5259 CVE-2015-5343 subversion: various flaws [fedora-all]
bugzilla·2015-12-16·CVSS 8.6
CVE-2015-5259 [HIGH] CVE-2015-5259 CVE-2015-5343 subversion: various flaws [fedora-all]
CVE-2015-5259 CVE-2015-5343 subversion: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
Bugzilla
CVE-2015-5343 subversion: (mod_dav_svn) integer overflow when parsing skel-encoded request bodies
bugzilla·2015-12-09·CVSS 7.6
CVE-2015-5343 [HIGH] CVE-2015-5343 subversion: (mod_dav_svn) integer overflow when parsing skel-encoded request bodies
CVE-2015-5343 subversion: (mod_dav_svn) integer overflow when parsing skel-encoded request bodies
The following flaw was reported in Subversion:
Subversion's httpd servers are vulnerable to a remotely triggerable heap-based buffer overflow and out-of-bounds read caused by an integer overflow when parsing skel-encoded request bodies.
This allows remote attackers with write access to a repository to cause a denial of service or possibly execute arbitrary code under the context of the httpd process. 32-bit server versions are vulnerable to both the denial-of-service attack and possible arbitrary code execution. 64-bit server versions are only vulnerable to the denial-of-service attack.
Acknowledgements:
Red Hat would like to thank the Apache Software Foundation for reporting this issue.
arXiv
Heuristic Approach Towards Countermeasure Selection using Attack Graphs
arxiv_fulltext·2019-06-26
Heuristic Approach Towards Countermeasure Selection using Attack Graphs
Heuristic Approach Towards Countermeasure Selection using Attack Graphs
Orly Stan, Ron Bitton, Michal Ezrets, Moran Dadon, Yuval Elovici, Asaf Shabtai
Dept. of Software and Information Systems Engineering
Ben-Gurion University of the Negev
Masaki Inokuchi, Yoshinobu Ohta, Tomohiko Yagyu
Security Research Laboratories, NEC Corporation
O. Stan, et al.
## Abstract
Selecting the optimal set of countermeasures is a challenging task that involves various considerations and tradeoffs such as prioritizing the risks to mitigate and costs.
The vast majority of studies for selecting a countermeasure deployment are based on a limited risk assessment procedure that utilizes the common vulnerability scoring system (CVSS).
Such a risk assessment procedure does not necessarily consider the prerequi
http://subversion.apache.org/security/CVE-2015-5343-advisory.txthttp://www.debian.org/security/2015/dsa-3424http://www.securitytracker.com/id/1034470http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.405261http://subversion.apache.org/security/CVE-2015-5343-advisory.txthttp://www.debian.org/security/2015/dsa-3424http://www.securitytracker.com/id/1034470http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.405261
2016-04-14
Published