CVE-2015-5343: Buffer Overflow
Integer overflow in util.c in moddavsvn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbitrary code via a skel-encoded request body, which triggers an out-of-bounds read and heap-based buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5343?
CVE-2015-5343 is classified as a medium severity vulnerability due to its potential to cause denial of service and possibly allow arbitrary code execution.
How do I fix CVE-2015-5343?
To fix CVE-2015-5343, upgrade Apache Subversion to version 1.8.15 or 1.9.3 or later.
Who is affected by CVE-2015-5343?
CVE-2015-5343 affects Apache Subversion versions 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3.
What type of attack can be executed via CVE-2015-5343?
CVE-2015-5343 can be exploited to perform denial of service attacks or potentially execute arbitrary code.
What component of Apache Subversion is affected by CVE-2015-5343?
CVE-2015-5343 affects the util.c component in the mod_dav_svn module of Apache Subversion.