Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2014-3528

Published: 5 August 2014

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.

Priority

Low

Status

Package Release Status
subversion
Launchpad, Ubuntu, Debian
lucid Ignored
(end of life)
precise
Released (1.6.17dfsg-3ubuntu3.4)
trusty
Released (1.8.8-1ubuntu3.1)
upstream
Released (1.7.18,1.8.10)
Patches:
upstream: http://svn.apache.org/viewvc?view=revision&revision=1605944
upstream: http://svn.apache.org/viewvc?view=revision&revision=1615193