CVE-2016-8734

MEDIUM

Apache Subversion <1.8.16, <1.9.4 - DoS

Title source: llm
STIX 2.1

Description

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94588
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037361
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2017/dsa-3932
Issue Tracking, Vendor Advisory x_refsource_confirm
https://subversion.apache.org/security/CVE-2016-8734-advisory.txt

Scores

CVSS v3 6.5
EPSS 0.1288
EPSS Percentile 94.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-400
Status published
Products (50)
apache/subversion 1.4.0
apache/subversion 1.4.1
apache/subversion 1.4.2
apache/subversion 1.4.3
apache/subversion 1.4.4
apache/subversion 1.4.5
apache/subversion 1.4.6
apache/subversion 1.5.0
apache/subversion 1.5.1
apache/subversion 1.5.2
... and 40 more
Published Oct 16, 2017
Tracked Since Feb 18, 2026