CVE-2016-8734
published 2017-10-16CVE-2016-8734: Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by…
PriorityP334medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
6.38%
92.9th percentile
Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.
Affected
94 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.8MEDIUM
vendor_ubuntu6.8MEDIUM
vendor_apache6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2017-08-11·CVSS 6.8
CVE-2016-2167 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in Subversion.
Joern Schneeweisz discovered that Subversion did not properly handle
host names in 'svn+ssh://' URLs. A remote attacker could use this
to construct a subversion repository that when accessed could run
arbitrary code with the privileges of the user. (CVE-2017-9800)
Daniel Shahaf and James McCoy discovered that Subversion did not
properly verify realms when using Cyrus SASL authentication. A
remote attacker could use this to possibly bypass intended access
restrictions. This issue only affected Ubuntu 14.04 LTS and Ubuntu
16.04 LTS. (CVE-2016-2167)
Florian Weimer discovered that Subversion clients did not properly
restrict XML entity expansion when accessing http(s):// URLs. A remote
attacker cou
Red Hat
subversion: unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s)://
vendor_redhat·2016-11-29·CVSS 6.5
CVE-2016-8734 [MEDIUM] CWE-776 subversion: unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s)://
subversion: unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s)://
Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.
Mitigation: Only Apache+Subversion servers that have the "DontDoThatConfigFile" configuration option present are affected by this flaw. This option is not enabled in default httpd or mod_dav_svn configuration as shipped with Red Hat Enterprise Linux.
Package: subversion (Red Hat Enterprise Linux 5) - Not affected
Package: subversion (Red Hat Enterprise Linux 6) - Not affected
Package: subversi
Debian
CVE-2016-8734: subversion - Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16,...
vendor_debian·2016·CVSS 6.5
CVE-2016-8734 [MEDIUM] CVE-2016-8734: subversion - Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16,...
Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.
Scope: local
bookworm: resolved (fixed in 1.9.5-1)
bullseye: resolved (fixed in 1.9.5-1)
forky: resolved (fixed in 1.9.5-1)
sid: resolved (fixed in 1.9.5-1)
trixie: resolved (fixed in 1.9.5-1)
Apache
Apache subversion: CVE-2016-8734
vendor_apache·CVSS 6.5
CVE-2016-8734 [MEDIUM] Apache subversion: CVE-2016-8734
Apache subversion: CVE-2016-8734
-advisory.txt [ PGP ] 1.4.0-1.8.16 and 1.9.0-1.9.4 Unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s):// sha1-advisory.txt 1.1.0-1.8.17 and 1.9.0-1.9.5 Apache Subversion is unable to store SHA1 collisions.
GHSA
GHSA-x5mc-4p5h-grh2: Apache Subversion's mod_dontdothat module and HTTP clients 1
ghsa_unreviewed·2022-05-13
CVE-2016-8734 [MEDIUM] CWE-400 GHSA-x5mc-4p5h-grh2: Apache Subversion's mod_dontdothat module and HTTP clients 1
Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.
OSV
CVE-2016-8734: Apache Subversion's mod_dontdothat module and HTTP clients 1
osv·2017-10-16·CVSS 6.5
CVE-2016-8734 [MEDIUM] CVE-2016-8734: Apache Subversion's mod_dontdothat module and HTTP clients 1
Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.
OSV
subversion vulnerabilities
osv·2017-08-11·CVSS 6.8
CVE-2017-9800 [MEDIUM] subversion vulnerabilities
subversion vulnerabilities
Joern Schneeweisz discovered that Subversion did not properly handle
host names in 'svn+ssh://' URLs. A remote attacker could use this
to construct a subversion repository that when accessed could run
arbitrary code with the privileges of the user. (CVE-2017-9800)
Daniel Shahaf and James McCoy discovered that Subversion did not
properly verify realms when using Cyrus SASL authentication. A
remote attacker could use this to possibly bypass intended access
restrictions. This issue only affected Ubuntu 14.04 LTS and Ubuntu
16.04 LTS. (CVE-2016-2167)
Florian Weimer discovered that Subversion clients did not properly
restrict XML entity expansion when accessing http(s):// URLs. A remote
attacker could use this to cause a denial of service. This issue only
affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8734 subversion: unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s):// [fedora-all]
bugzilla·2016-11-29·CVSS 6.5
CVE-2016-8734 [MEDIUM] CVE-2016-8734 subversion: unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s):// [fedora-all]
CVE-2016-8734 subversion: unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s):// [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
Bugzilla
CVE-2016-8734 subversion: unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s)://
bugzilla·2016-11-22·CVSS 6.5
CVE-2016-8734 [MEDIUM] CVE-2016-8734 subversion: unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s)://
CVE-2016-8734 subversion: unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s)://
It was discovered that Subversion's mod_dontdothat module and Subversion clients using http(s):// are vulnerable to a denial-of-service attack caused by exponential XML entity expansion.
An authenticated remote attacker can cause denial-of-service conditions on the server using mod_dontdothat by sending a specially crafted REPORT request. The attack does not require access to a particular repository.
If an attacker has control over HTTP responses sent to a Subversion client, they can cause denial-of-service conditions on the client by injecting an XML bomb into the response.
Upstream bug:
https://issues.apache.org/jira/browse/SVN-4630
Discussion:
Acknowledgments:
Na
Bugzilla
mod_dav_svn: unrestricted internal XML entities expansion
bugzilla·2012-12-19
mod_dav_svn: unrestricted internal XML entities expansion
mod_dav_svn: unrestricted internal XML entities expansion
In subversion 1.7.7 in tools/server-side/mod_dontdothat/mod_dontdothat.c, there is the following code:
ctx->xmlp = XML_ParserCreate(NULL);
apr_pool_cleanup_register(r->pool, ctx->xmlp,
clean_up_parser,
apr_pool_cleanup_null);
XML_SetUserData(ctx->xmlp, ctx);
XML_SetElementHandler(ctx->xmlp, start_element, end_element);
XML_SetCharacterDataHandler(ctx->xmlp, cdata);
This doesn't disable entity expansion for the internal DTD subset, so there is a denial-of-service vector ("billion laughs attack"). I'm marking this as a security bug because it probably allows to crash Apache or trigger the kernel OOM handler. This should probably be fixed in coordination with Subversion upstream.
Adding the following handler using
XML_SetEntityDec
http://www.debian.org/security/2017/dsa-3932http://www.securityfocus.com/bid/94588http://www.securitytracker.com/id/1037361https://lists.apache.org/thread.html/7798f5cda1b2a3c70db4be77694b12dec8fcc1a441b00009d44f0e09%40%3Cannounce.apache.org%3Ehttps://subversion.apache.org/security/CVE-2016-8734-advisory.txthttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://www.debian.org/security/2017/dsa-3932http://www.securityfocus.com/bid/94588http://www.securitytracker.com/id/1037361https://lists.apache.org/thread.html/7798f5cda1b2a3c70db4be77694b12dec8fcc1a441b00009d44f0e09%40%3Cannounce.apache.org%3Ehttps://subversion.apache.org/security/CVE-2016-8734-advisory.txthttps://www.oracle.com/security-alerts/cpuoct2020.html
2017-10-16
Published