CVE-2015-5259: Apache Subversion

High severity, CVSS 8.6. EPSS: 57% chance of exploitation in the next 30 days.

Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// protocol string, which triggers a heap-based buffer overflow and an out-of-bounds read.

Affected products

  • Apache Subversion: version 1.9.0 only; version 1.9.1 only; version 1.9.2 only

Published 2016-01-08. Last modified 2026-06-17.