ISOMAN

CVE

CVE-2014-3528

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.

Severity
MEDIUM
CVSS
4
Published
Modified

Linked Releases

References

  1. http://lists.apple.com/archives/security-announce/2015/Mar/msg00003.html
  2. http://lists.opensuse.org/opensuse-updates/2014-08/msg00038.html
  3. http://rhn.redhat.com/errata/RHSA-2015-0165.html
  4. http://rhn.redhat.com/errata/RHSA-2015-0166.html
  5. http://secunia.com/advisories/59432
  6. http://secunia.com/advisories/59584
  7. http://secunia.com/advisories/60722
  8. http://subversion.apache.org/security/CVE-2014-3528-advisory.txt
  9. http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
  10. http://www.securityfocus.com/bid/68995
  11. http://www.ubuntu.com/usn/USN-2316-1
  12. https://security.gentoo.org/glsa/201610-05
  13. https://support.apple.com/HT204427
  14. http://lists.apple.com/archives/security-announce/2015/Mar/msg00003.html
  15. http://lists.opensuse.org/opensuse-updates/2014-08/msg00038.html
  16. http://rhn.redhat.com/errata/RHSA-2015-0165.html
  17. http://rhn.redhat.com/errata/RHSA-2015-0166.html
  18. http://secunia.com/advisories/59432
  19. http://secunia.com/advisories/59584
  20. http://secunia.com/advisories/60722