CVE-2015-5343
HIGHApache Subversion <1.8.15-1.9.3 - DoS
Title source: llmDescription
Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbitrary code via a skel-encoded request body, which triggers an out-of-bounds read and heap-based buffer overflow.
References (4)
Scores
CVSS v3
7.6
EPSS
0.1909
EPSS Percentile
95.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Classification
CWE
CWE-119
Status
draft
Affected Products (2)
apache/subversion
< 1.7.20
debian/debian_linux
Timeline
Published
Apr 14, 2016
Tracked Since
Feb 18, 2026