CVE-2016-2168
published 2016-05-05CVE-2016-2168: The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote…
PriorityP340medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
19.63%
97.1th percentile
The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a crafted header in a (1) MOVE or (2) COPY request, involving an authorization check.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | <= 1.8.15 | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.9.4-1 | 1.9.4-1 |
| apache | subversion | >= 0 < 1.9.4-1 | 1.9.4-1 |
| apache | subversion | >= 0 < 1.9.4-1 | 1.9.4-1 |
| apache | subversion | >= 0 < 1.9.4-1 | 1.9.4-1 |
| debian | subversion | < subversion 1.9.4-1 (bookworm) | subversion 1.9.4-1 (bookworm) |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_ubuntu6.8MEDIUM
vendor_apache6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2017-10-24·CVSS 6.8
CVE-2016-2167 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in Subversion.
USN-3388-1 fixed several vulnerabilities in Subversion. This update
provides the corresponding update for Ubuntu 12.04 ESM.
Ivan Zhakov discovered that Subversion did not properly handle
some requests. A remote attacker could use this to cause a
denial of service. (CVE-2016-2168)
Original advisory details:
Joern Schneeweisz discovered that Subversion did not properly handle
host names in 'svn+ssh://' URLs. A remote attacker could use this
to construct a subversion repository that when accessed could run
arbitrary code with the privileges of the user. (CVE-2017-9800)
Daniel Shahaf and James McCoy discovered that Subversion did not
properly verify realms when using Cyrus SASL authentication. A
Red Hat
subversion: DoS in mod_authz_svn during COPY/MOVE authorization check
vendor_redhat·2016-04-28·CVSS 6.5
CVE-2016-2168 [MEDIUM] CWE-20 subversion: DoS in mod_authz_svn during COPY/MOVE authorization check
subversion: DoS in mod_authz_svn during COPY/MOVE authorization check
The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a crafted header in a (1) MOVE or (2) COPY request, involving an authorization check.
Package: subversion (Red Hat Enterprise Linux 5) - Will not fix
Package: subversion (Red Hat Enterprise Linux 6) - Will not fix
Package: subversion (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-2168: subversion - The req_check_access function in the mod_authz_svn module in the httpd server in...
vendor_debian·2016·CVSS 6.5
CVE-2016-2168 [MEDIUM] CVE-2016-2168: subversion - The req_check_access function in the mod_authz_svn module in the httpd server in...
The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a crafted header in a (1) MOVE or (2) COPY request, involving an authorization check.
Scope: local
bookworm: resolved (fixed in 1.9.4-1)
bullseye: resolved (fixed in 1.9.4-1)
forky: resolved (fixed in 1.9.4-1)
sid: resolved (fixed in 1.9.4-1)
trixie: resolved (fixed in 1.9.4-1)
Apache
Apache subversion: CVE-2016-2168
vendor_apache·CVSS 6.5
CVE-2016-2168 [MEDIUM] Apache subversion: CVE-2016-2168
Apache subversion: CVE-2016-2168
-advisory.txt 1.0.0-1.8.15 and 1.9.0-1.9.3 Remotely triggerable DoS vulnerability in mod_authz_svn during COPY/MOVE authorization check.
GHSA
GHSA-h8ww-x8qq-fcxm: The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1
ghsa_unreviewed·2022-05-13
CVE-2016-2168 [MEDIUM] GHSA-h8ww-x8qq-fcxm: The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1
The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a crafted header in a (1) MOVE or (2) COPY request, involving an authorization check.
OSV
CVE-2016-2168: The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1
osv·2016-05-05·CVSS 6.5
CVE-2016-2168 [MEDIUM] CVE-2016-2168: The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1
The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a crafted header in a (1) MOVE or (2) COPY request, involving an authorization check.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2167 CVE-2016-2168 subversion: various flaws [fedora-all]
bugzilla·2016-04-29·CVSS 6.8
CVE-2016-2167 [MEDIUM] CVE-2016-2167 CVE-2016-2168 subversion: various flaws [fedora-all]
CVE-2016-2167 CVE-2016-2168 subversion: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
Bugzilla
CVE-2016-2168 subversion: DoS in mod_authz_svn during COPY/MOVE authorization check
bugzilla·2016-04-29·CVSS 6.5
CVE-2016-2168 [MEDIUM] CVE-2016-2168 subversion: DoS in mod_authz_svn during COPY/MOVE authorization check
CVE-2016-2168 subversion: DoS in mod_authz_svn during COPY/MOVE authorization check
A denial of service flaw was found in Subversion's mod_authz_svn module. A remote attacker could use a COPY or MOVE request with a specially crafted header that, when processed by Subversion during an authentication check, could cause the Subversion server to crash.
External References:
https://subversion.apache.org/security/CVE-2016-2168-advisory.txt
Discussion:
Created subversion tracking bugs for this issue:
Affects: fedora-all [bug 1331687]
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184545.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00043.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00044.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-announce/201604.mbox/%3CCAP_GPNgJet+7_MAhomFVOXPgLtewcUw9w=k9zdPCkq5tvPxVMA%40mail.gmail.com%3Ehttp://mail-archives.apache.org/mod_mbox/subversion-announce/201604.mbox/%3CCAP_GPNgfn1iKueW51EpmXzXi_URNfGNofZSgOyW1_jnSeNm5DQ%40mail.gmail.com%3Ehttp://subversion.apache.org/security/CVE-2016-2168-advisory.txthttp://www.debian.org/security/2016/dsa-3561http://www.securityfocus.com/bid/89320http://www.securitytracker.com/id/1035707http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.417496https://security.gentoo.org/glsa/201610-05https://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-May/184545.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00043.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00044.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-announce/201604.mbox/%3CCAP_GPNgJet+7_MAhomFVOXPgLtewcUw9w=k9zdPCkq5tvPxVMA%40mail.gmail.com%3Ehttp://mail-archives.apache.org/mod_mbox/subversion-announce/201604.mbox/%3CCAP_GPNgfn1iKueW51EpmXzXi_URNfGNofZSgOyW1_jnSeNm5DQ%40mail.gmail.com%3Ehttp://subversion.apache.org/security/CVE-2016-2168-advisory.txthttp://www.debian.org/security/2016/dsa-3561http://www.securityfocus.com/bid/89320http://www.securitytracker.com/id/1035707http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.417496https://security.gentoo.org/glsa/201610-05https://www.oracle.com/security-alerts/cpuoct2020.html
2016-05-05
Published