VDB

DEBIAN-CVE-2014-3528

DEBIAN-CVE-2014-3528 PUBLISHED

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.

Affected Products

VendorProductVersions
Debian:12subversion0, 0, 0
Debian:13subversion0, 0, 0
Debian:14subversion0, 0, 0
Debian:11subversion0, 0, 0

Timeline

  • Aug 19, 2014 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›