CVE-2015-5259
HIGHApache Subversion <1.9.3 - RCE
Title source: llmDescription
Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// protocol string, which triggers a heap-based buffer overflow and an out-of-bounds read.
References (4)
Scores
CVSS v3
8.6
EPSS
0.4068
EPSS Percentile
97.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Classification
CWE
CWE-119
CWE-189
Status
draft
Affected Products (3)
apache/subversion
apache/subversion
apache/subversion
Timeline
Published
Jan 08, 2016
Tracked Since
Feb 18, 2026