VulnerabilityModified
CVE-2014-3528
Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication…
MEDIUM 4.0EPSS 7.40%
Does this matter?
Lower severity and a low EPSS score (7.40%). Track it; it rarely justifies an emergency change on its own.
Description
Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
- EPSS
- 7.40% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- opensuse/opensuse · apache/subversion · canonical/ubuntu linux · apple/xcode · redhat/enterprise linux desktop · redhat/enterprise linux hpc node · redhat/enterprise linux server · redhat/enterprise linux server eus · redhat/enterprise linux workstation
- Source
- secalert@redhat.com
References
- http://lists.apple.com/archives/security-announce/2015/Mar/msg00003.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-08/msg00038.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0165.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0166.htmlThird Party Advisory
- http://secunia.com/advisories/59432
- http://secunia.com/advisories/59584
- http://secunia.com/advisories/60722
- http://subversion.apache.org/security/CVE-2014-3528-advisory.txtVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
- http://www.securityfocus.com/bid/68995
- http://www.ubuntu.com/usn/USN-2316-1Vendor Advisory
- https://security.gentoo.org/glsa/201610-05
- https://support.apple.com/HT204427Third Party Advisory
- http://lists.apple.com/archives/security-announce/2015/Mar/msg00003.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-08/msg00038.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0165.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0166.htmlThird Party Advisory
- http://secunia.com/advisories/59432
- http://secunia.com/advisories/59584
- http://secunia.com/advisories/60722
- http://subversion.apache.org/security/CVE-2014-3528-advisory.txtVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
- http://www.securityfocus.com/bid/68995
- http://www.ubuntu.com/usn/USN-2316-1Vendor Advisory
- https://security.gentoo.org/glsa/201610-05
- https://support.apple.com/HT204427Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.