CVE-2016-2167
published 2016-05-05CVE-2016-2167: The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used…
PriorityP348medium6.8CVSS 3.0
AVNACHPRLUINSUCHIHAN
EPSS
6.81%
93.3th percentile
The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm string that is a prefix of an expected repository realm string.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | <= 1.8.15 | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.9.4-1 | 1.9.4-1 |
| apache | subversion | >= 0 < 1.9.4-1 | 1.9.4-1 |
| apache | subversion | >= 0 < 1.9.4-1 | 1.9.4-1 |
| apache | subversion | >= 0 < 1.9.4-1 | 1.9.4-1 |
| apache | subversion | >= 0 < 1.8.8-1ubuntu3.3 | 1.8.8-1ubuntu3.3 |
| apache | subversion | >= 0 < 1.9.3-2ubuntu1.1 | 1.9.3-2ubuntu1.1 |
| debian | subversion | < subversion 1.9.4-1 (bookworm) | subversion 1.9.4-1 (bookworm) |
CVSS provenance
nvdv3.06.8MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
osv6.8MEDIUM
vendor_apache6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2017-10-24·CVSS 6.8
CVE-2016-2167 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in Subversion.
USN-3388-1 fixed several vulnerabilities in Subversion. This update
provides the corresponding update for Ubuntu 12.04 ESM.
Ivan Zhakov discovered that Subversion did not properly handle
some requests. A remote attacker could use this to cause a
denial of service. (CVE-2016-2168)
Original advisory details:
Joern Schneeweisz discovered that Subversion did not properly handle
host names in 'svn+ssh://' URLs. A remote attacker could use this
to construct a subversion repository that when accessed could run
arbitrary code with the privileges of the user. (CVE-2017-9800)
Daniel Shahaf and James McCoy discovered that Subversion did not
properly verify realms when using Cyrus SASL authentication. A
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2017-08-11·CVSS 6.8
CVE-2016-2167 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in Subversion.
Joern Schneeweisz discovered that Subversion did not properly handle
host names in 'svn+ssh://' URLs. A remote attacker could use this
to construct a subversion repository that when accessed could run
arbitrary code with the privileges of the user. (CVE-2017-9800)
Daniel Shahaf and James McCoy discovered that Subversion did not
properly verify realms when using Cyrus SASL authentication. A
remote attacker could use this to possibly bypass intended access
restrictions. This issue only affected Ubuntu 14.04 LTS and Ubuntu
16.04 LTS. (CVE-2016-2167)
Florian Weimer discovered that Subversion clients did not properly
restrict XML entity expansion when accessing http(s):// URLs. A remote
attacker cou
Red Hat
subversion: svnserve/sasl may authenticate users using the wrong realm
vendor_redhat·2016-04-28·CVSS 6.8
CVE-2016-2167 [MEDIUM] CWE-20 subversion: svnserve/sasl may authenticate users using the wrong realm
subversion: svnserve/sasl may authenticate users using the wrong realm
The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm string that is a prefix of an expected repository realm string.
Package: subversion (Red Hat Enterprise Linux 5) - Will not fix
Package: subversion (Red Hat Enterprise Linux 6) - Will not fix
Package: subversion (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-2167: subversion - The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion...
vendor_debian·2016·CVSS 6.8
CVE-2016-2167 [MEDIUM] CVE-2016-2167: subversion - The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion...
The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm string that is a prefix of an expected repository realm string.
Scope: local
bookworm: resolved (fixed in 1.9.4-1)
bullseye: resolved (fixed in 1.9.4-1)
forky: resolved (fixed in 1.9.4-1)
sid: resolved (fixed in 1.9.4-1)
trixie: resolved (fixed in 1.9.4-1)
Apache
Apache subversion: CVE-2016-2167
vendor_apache·CVSS 6.8
CVE-2016-2167 [MEDIUM] Apache subversion: CVE-2016-2167
Apache subversion: CVE-2016-2167
-advisory.txt 1.5.0-1.8.15 and 1.9.0-1.9.3 svnserve/sasl may authenticate users using the wrong realm.
GHSA
GHSA-4j43-22vc-mh3h: The canonicalize_username function in svnserve/cyrus_auth
ghsa_unreviewed·2022-05-13
CVE-2016-2167 [MEDIUM] CWE-284 GHSA-4j43-22vc-mh3h: The canonicalize_username function in svnserve/cyrus_auth
The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm string that is a prefix of an expected repository realm string.
OSV
subversion vulnerabilities
osv·2017-08-11·CVSS 6.8
CVE-2017-9800 [MEDIUM] subversion vulnerabilities
subversion vulnerabilities
Joern Schneeweisz discovered that Subversion did not properly handle
host names in 'svn+ssh://' URLs. A remote attacker could use this
to construct a subversion repository that when accessed could run
arbitrary code with the privileges of the user. (CVE-2017-9800)
Daniel Shahaf and James McCoy discovered that Subversion did not
properly verify realms when using Cyrus SASL authentication. A
remote attacker could use this to possibly bypass intended access
restrictions. This issue only affected Ubuntu 14.04 LTS and Ubuntu
16.04 LTS. (CVE-2016-2167)
Florian Weimer discovered that Subversion clients did not properly
restrict XML entity expansion when accessing http(s):// URLs. A remote
attacker could use this to cause a denial of service. This issue only
affected
OSV
CVE-2016-2167: The canonicalize_username function in svnserve/cyrus_auth
osv·2016-05-05·CVSS 6.8
CVE-2016-2167 [MEDIUM] CVE-2016-2167: The canonicalize_username function in svnserve/cyrus_auth
The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm string that is a prefix of an expected repository realm string.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2167 CVE-2016-2168 subversion: various flaws [fedora-all]
bugzilla·2016-04-29·CVSS 6.8
CVE-2016-2167 [MEDIUM] CVE-2016-2167 CVE-2016-2168 subversion: various flaws [fedora-all]
CVE-2016-2167 CVE-2016-2168 subversion: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
Bugzilla
CVE-2016-2167 subversion: svnserve/sasl may authenticate users using the wrong realm
bugzilla·2016-04-29·CVSS 6.8
CVE-2016-2167 [MEDIUM] CVE-2016-2167 subversion: svnserve/sasl may authenticate users using the wrong realm
CVE-2016-2167 subversion: svnserve/sasl may authenticate users using the wrong realm
It was found that authentication against the Cyrus SASL library would permit a remote user to specify a realm string which is a prefix of the expected realm string. Consequently, a user who has valid credentials to a realm, whose name is a prefix of the repository's realm, would be able to successfully authenticate to the repository.
External References:
https://subversion.apache.org/security/CVE-2016-2167-advisory.txt
Discussion:
Created subversion tracking bugs for this issue:
Affects: fedora-all [bug 1331687]
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184545.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00043.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00044.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-announce/201604.mbox/%3CCAP_GPNgJet+7_MAhomFVOXPgLtewcUw9w=k9zdPCkq5tvPxVMA%40mail.gmail.com%3Ehttp://mail-archives.apache.org/mod_mbox/subversion-announce/201604.mbox/%3CCAP_GPNgfn1iKueW51EpmXzXi_URNfGNofZSgOyW1_jnSeNm5DQ%40mail.gmail.com%3Ehttp://subversion.apache.org/security/CVE-2016-2167-advisory.txthttp://www.debian.org/security/2016/dsa-3561http://www.securityfocus.com/bid/89417http://www.securitytracker.com/id/1035706http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.417496https://security.gentoo.org/glsa/201610-05https://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-May/184545.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00043.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00044.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-announce/201604.mbox/%3CCAP_GPNgJet+7_MAhomFVOXPgLtewcUw9w=k9zdPCkq5tvPxVMA%40mail.gmail.com%3Ehttp://mail-archives.apache.org/mod_mbox/subversion-announce/201604.mbox/%3CCAP_GPNgfn1iKueW51EpmXzXi_URNfGNofZSgOyW1_jnSeNm5DQ%40mail.gmail.com%3Ehttp://subversion.apache.org/security/CVE-2016-2167-advisory.txthttp://www.debian.org/security/2016/dsa-3561http://www.securityfocus.com/bid/89417http://www.securitytracker.com/id/1035706http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.417496https://security.gentoo.org/glsa/201610-05https://www.oracle.com/security-alerts/cpuoct2020.html
2016-05-05
Published