CPANSA-Alien-SVN-2014-3528-svn: Alien-SVN vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2014-08-19T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2014-08-19T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | Severity | ||
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.
Vulnerabilities
CVE-2014-3528
Vulnerability DescriptionApache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.
| Weakness | CWE-255 : Credentials Management Errors |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Alien-SVN greater than or equal 1.4.5.0 and less than or equal 1.4.5.3 |
|
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Alien-SVN-2014-3528-svn JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2014/cpansa-alien-svn-2014-3528-svn.json - http://subversion.apache.org/security/CVE-2014-3528-advisory.txt external
http://subversion.apache.org/security/CVE-2014-3528-advisory.txt - http://www.ubuntu.com/usn/USN-2316-1 external
http://www.ubuntu.com/usn/USN-2316-1 - http://secunia.com/advisories/60722 external
http://secunia.com/advisories/60722 - http://lists.opensuse.org/opensuse-updates/2014-08/msg00038.html external
http://lists.opensuse.org/opensuse-updates/2014-08/msg00038.html - http://lists.apple.com/archives/security-announce/2015/Mar/msg00003.html external
http://lists.apple.com/archives/security-announce/2015/Mar/msg00003.html - https://support.apple.com/HT204427 external
https://support.apple.com/HT204427 - http://rhn.redhat.com/errata/RHSA-2015-0166.html external
http://rhn.redhat.com/errata/RHSA-2015-0166.html - http://rhn.redhat.com/errata/RHSA-2015-0165.html external
http://rhn.redhat.com/errata/RHSA-2015-0165.html - http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html external
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html - http://www.securityfocus.com/bid/68995 external
http://www.securityfocus.com/bid/68995 - http://secunia.com/advisories/59584 external
http://secunia.com/advisories/59584 - http://secunia.com/advisories/59432 external
http://secunia.com/advisories/59432 - https://security.gentoo.org/glsa/201610-05 external
https://security.gentoo.org/glsa/201610-05 - CVE-2014-3528 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2014-3528
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Tue Aug 19 00:00:00 2014 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/