imPC@ndo IT

Tracker / CVE-2015-5343

CVE-2015-5343

High 7.6

Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbitrary code via a skel-encoded request body, which triggers an out-of-bounds read and heap-based buffer overflow.

Affected products and versions

apache subversion · 1.7.0 → 1.7.20
apache subversion · 1.8.0 → 1.8.15
apache subversion · 1.9.0 → 1.9.3
debian debian_linux

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References