It was discovered that the Subversion moddavsvn module incorrectly handled REPORT requests for a resource that does not exist. A remote attacker could use this issue to cause the server to crash, resulting in a denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-3580)
It was discovered that the Subversion moddavsvn module incorrectly handled requests requiring a lookup for a virtual transaction name that does not exist. A remote attacker could use this issue to cause the server to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-8108)
Evgeny Kotkov discovered that the Subversion moddavsvn module incorrectly handled large numbers of REPORT requests. A remote attacker could use this issue to cause the server to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-0202)
Evgeny Kotkov discovered that the Subversion moddavsvn and svnserve modules incorrectly certain crafted parameter combinations. A remote attacker could use this issue to cause the server to crash, resulting in a denial of service. (CVE-2015-0248)
Ivan Zhakov discovered that the Subversion moddavsvn module incorrectly handled crafted v1 HTTP protocol request sequences. A remote attacker could use this issue to spoof the svn:author property. (CVE-2015-0251)
C. Michael Pilato discovered that the Subversion moddavsvn module incorrectly restricted anonymous access. A remote attacker could use this issue to read hidden files via the path name. This issue only affected Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-3184)
C. Michael Pilato discovered that Subversion incorrectly handled path-based authorization. A remote attacker could use this issue to obtain sensitive path information. (CVE-2015-3187)
{
"binaries": [
{
"binary_version": "1.8.8-1ubuntu3.2",
"binary_name": "libapache2-mod-svn"
},
{
"binary_version": "1.8.8-1ubuntu3.2",
"binary_name": "libapache2-svn"
},
{
"binary_version": "1.8.8-1ubuntu3.2",
"binary_name": "libsvn-dev"
},
{
"binary_version": "1.8.8-1ubuntu3.2",
"binary_name": "libsvn-java"
},
{
"binary_version": "1.8.8-1ubuntu3.2",
"binary_name": "libsvn-perl"
},
{
"binary_version": "1.8.8-1ubuntu3.2",
"binary_name": "libsvn-ruby1.8"
},
{
"binary_version": "1.8.8-1ubuntu3.2",
"binary_name": "libsvn1"
},
{
"binary_version": "1.8.8-1ubuntu3.2",
"binary_name": "python-subversion"
},
{
"binary_version": "1.8.8-1ubuntu3.2",
"binary_name": "ruby-svn"
},
{
"binary_version": "1.8.8-1ubuntu3.2",
"binary_name": "subversion"
},
{
"binary_version": "1.8.8-1ubuntu3.2",
"binary_name": "subversion-tools"
}
],
"availability": "No subscription required"
}
{
"ecosystem": "Ubuntu:14.04:LTS",
"cves": [
{
"id": "CVE-2014-3580",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2014-8108",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2015-0202",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2015-0248",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2015-0251",
"severity": [
{
"type": "Ubuntu",
"score": "low"
}
]
},
{
"id": "CVE-2015-3184",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2015-3187",
"severity": [
{
"type": "Ubuntu",
"score": "medium"
}
]
}
]
}