CVE-2015-5343: Apache Subversion

High severity, CVSS 7.6. EPSS: 30.2% chance of exploitation in the next 30 days.

Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbitrary code via a skel-encoded request body, which triggers an out-of-bounds read and heap-based buffer overflow.

Affected products

  • Apache Subversion: from 1.7.0, up to and including 1.7.20; from 1.8.0, before 1.8.15 (fixed in 1.8.15); from 1.9.0, before 1.9.3 (fixed in 1.9.3)
  • Debian Debian Linux: version 8.0 only

Published 2016-04-14. Last modified 2026-06-17.