Description
Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbitrary code via a skel-encoded request body, which triggers an out-of-bounds read and heap-based buffer overflow.
In plain language
AI Worth attentionCVE-2015-5343 is a Subversion server bug that a logged-in user could use to crash the server; if you run Apache Subversion (mod_dav_svn), you should update because it’s a denial-of-service risk.
CVE-2015-5343 is an integer overflow in util.c within mod_dav_svn (Apache Subversion) that can be triggered by a remote authenticated client to cause denial of service (and possibly more serious memory corruption) via a crafted request body.
What to do now
- Check whether you run Apache Subversion with the WebDAV module (mod_dav_svn) on this server.
- Check your installed Subversion version; treat any of these as potentially affected: 1.7.x, 1.8.x before 1.8.15, or 1.9.x before 1.9.3.
- Upgrade Subversion to a fixed version: 1.8.15 or newer, or 1.9.3 or newer (follow your vendor’s package instructions for Debian).
- After upgrading, restart the Subversion service/Apache and verify the service is responding (and that users can still access repositories).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:LConfidentialityI:LIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2015-5343 and every CVE in our database. Create a free account — no credit card required.
Create Free Account