CVE-2014-3528

Severity

40%

Complexity

49%

Confidentiality

81%

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.

CVSS 2.0 Base Score 4. CVSS Attack Vector: network. CVSS Attack Complexity: high. CVSS Vector: (AV:N/AC:H/Au:N/C:P/I:P/A:N).

Overview

First reported 10 years ago

2014-08-19 18:55:00

Last updated 6 years ago

2018-10-30 16:27:00

Affected Software

OpenSUSE 12.3

12.3

OpenSUSE 13.1

13.1

Apache Software Foundation Subversion 1.0.0

1.0.0

Apache Software Foundation Subversion 1.0.1

1.0.1

Apache Software Foundation Subversion 1.0.2

1.0.2

Apache Software Foundation Subversion 1.0.3

1.0.3

Apache Software Foundation Subversion 1.0.4

1.0.4

Apache Software Foundation Subversion 1.0.5

1.0.5

Apache Software Foundation Subversion 1.0.6

1.0.6

Apache Software Foundation Subversion 1.0.7

1.0.7

Apache Software Foundation Subversion 1.0.8

1.0.8

Apache Software Foundation Subversion 1.0.9

1.0.9

Apache Software Foundation Subversion 1.1.0

1.1.0

Apache Software Foundation Subversion 1.1.1

1.1.1

Apache Software Foundation Subversion 1.1.2

1.1.2

Apache Software Foundation Subversion 1.1.3

1.1.3

Apache Software Foundation Subversion 1.1.4

1.1.4

Apache Software Foundation Subversion 1.2.0

1.2.0

Apache Software Foundation Subversion 1.2.1

1.2.1

Apache Software Foundation Subversion 1.2.2

1.2.2

Apache Software Foundation Subversion 1.2.3

1.2.3

Apache Software Foundation Subversion 1.3.0

1.3.0

Apache Software Foundation Subversion 1.3.1

1.3.1

Apache Software Foundation Subversion 1.3.2

1.3.2

Apache Software Foundation Subversion 1.4.0

1.4.0

Apache Software Foundation Subversion 1.4.1

1.4.1

Apache Software Foundation Subversion 1.4.2

1.4.2

Apache Software Foundation Subversion 1.4.3

1.4.3

Apache Software Foundation Subversion 1.4.4

1.4.4

Apache Software Foundation Subversion 1.4.5

1.4.5

Apache Software Foundation Subversion 1.4.6

1.4.6

Apache Software Foundation Subversion 1.5.0

1.5.0

Apache Software Foundation Subversion 1.5.1

1.5.1

Apache Software Foundation Subversion 1.5.2

1.5.2

Apache Software Foundation Subversion 1.5.3

1.5.3

Apache Software Foundation Subversion 1.5.4

1.5.4

Apache Software Foundation Subversion 1.5.5

1.5.5

Apache Software Foundation Subversion 1.5.6

1.5.6

Apache Software Foundation Subversion 1.5.7

1.5.7

Apache Software Foundation Subversion 1.5.8

1.5.8

Apache Software Foundation Subversion 1.6.0

1.6.0

Apache Software Foundation Subversion 1.6.1

1.6.1

Apache Software Foundation Subversion 1.6.2

1.6.2

Apache Software Foundation Subversion 1.6.3

1.6.3

Apache Software Foundation Subversion 1.6.4

1.6.4

Apache Software Foundation Subversion 1.6.5

1.6.5

Apache Software Foundation Subversion 1.6.6

1.6.6

Apache Software Foundation Subversion 1.6.7

1.6.7

Apache Software Foundation Subversion 1.6.8

1.6.8

Apache Software Foundation Subversion 1.6.9

1.6.9

Apache Software Foundation Subversion 1.6.10

1.6.10

Apache Software Foundation Subversion 1.6.11

1.6.11

Apache Software Foundation Subversion 1.6.12

1.6.12

Apache Software Foundation Subversion 1.6.13

1.6.13

Apache Software Foundation Subversion 1.6.14

1.6.14

Apache Software Foundation Subversion 1.6.15

1.6.15

Apache Software Foundation Subversion 1.6.16

1.6.16

Apache Software Foundation Subversion 1.6.17

1.6.17

Apache Software Foundation Subversion 1.6.18

1.6.18

Apache Software Foundation Subversion 1.6.19

1.6.19

Apache Software Foundation Subversion 1.6.20

1.6.20

Apache Software Foundation Subversion 1.6.21

1.6.21

Apache Software Foundation Subversion 1.6.23

1.6.23

Apache Software Foundation Subversion 1.7.0

1.7.0

Apache Software Foundation Subversion 1.7.1

1.7.1

Apache Software Foundation Subversion 1.7.2

1.7.2

Apache Software Foundation Subversion 1.7.3

1.7.3

Apache Software Foundation Subversion 1.7.4

1.7.4

Apache Software Foundation Subversion 1.7.5

1.7.5

Apache Software Foundation Subversion 1.7.6

1.7.6

Apache Software Foundation Subversion 1.7.7

1.7.7

Apache Software Foundation Subversion 1.7.8

1.7.8

Apache Software Foundation Subversion 1.7.9

1.7.9

Apache Software Foundation Subversion 1.7.10

1.7.10

Apache Software Foundation Subversion 1.7.11

1.7.11

Apache Software Foundation Subversion 1.7.12

1.7.12

Apache Software Foundation Subversion 1.7.13

1.7.13

Apache Software Foundation Subversion 1.7.14

1.7.14

Apache Software Foundation Subversion 1.7.15

1.7.15

Apache Software Foundation Subversion 1.7.16

1.7.16

Apache Software Foundation Subversion 1.7.17

1.7.17

Apache Software Foundation Subversion 1.8.0

1.8.0

Apache Software Foundation Subversion 1.8.1

1.8.1

Apache Software Foundation Subversion 1.8.2

1.8.2

Apache Software Foundation Subversion 1.8.3

1.8.3

Apache Software Foundation Subversion 1.8.4

1.8.4

Apache Software Foundation Subversion 1.8.5

1.8.5

Apache Software Foundation Subversion 1.8.6

1.8.6

Apache Software Foundation Subversion 1.8.7

1.8.7

Apache Software Foundation Subversion 1.8.8

1.8.8

Apache Software Foundation Subversion 1.8.9

1.8.9

Canonical Ubuntu Linux 12.04 LTS (Long-Term Support)

12.04

Canonical Ubuntu Linux 14.04 LTS (Long-Term Support)

14.04

Apple Xcode 6.1.1

6.1.1

Red Hat Enterprise Linux Desktop 6.0

6.0

RedHat Enterprise Linux Desktop 7.0

7.0

RedHat Enterprise Linux HPC Node 6.0

6.0

RedHat Enterprise Linux HPC Node 7.0

7.0

Red Hat Enterprise Linux Server 6.0

6.0

RedHat Enterprise Linux Server 7.0

7.0

Red Hat Enterprise Linux Workstation 6.0

6.0

RedHat Enterprise Linux Workstation 7.0

7.0

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.