Bug 889849 (CVE-2014-3528) - VUL-0: CVE-2014-3528: subversion: Apache Subversion might reveal authentication information through md5 collision attack on authentication realm
Summary: VUL-0: CVE-2014-3528: subversion: Apache Subversion might reveal authenticati...
Status: RESOLVED FIXED
Alias: CVE-2014-3528
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: All Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2014-08-29
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:sle11-sp3:58608
Keywords:
Depends on:
Blocks:
 
Reported: 2014-07-31 22:35 UTC by Andreas Stieger
Modified: 2014-09-08 13:00 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2014-07-31 22:35:49 UTC
User-Agent:       Mozilla/5.0 (X11; Linux i686; rv:30.0) Gecko/20100101 Firefox/30.0

Apache Subversion might reveal authentication information through an md5 collision attack on authentication realm.

An attacker would need to trick the potential victim to connect to a subversion repository he controls and present a special realm string to be transmitted authentication information.

Patches:
http://svn.apache.org/r1550691
http://svn.apache.org/r1550772

Reference:
http://mail-archives.apache.org/mod_mbox/subversion-dev/201407.mbox/%3C53DAB4A7.8030004%40reser.org%3E

Reproducible: Didn't try
Comment 1 Marcus Meissner 2014-08-01 07:54:57 UTC
does this have a CVE already? if not we would ask on oss-sec
Comment 2 Andreas Stieger 2014-08-01 08:19:28 UTC
(In reply to comment #1)
> does this have a CVE already? if not we would ask on oss-sec

Not that I am aware of. security@apache.org was asked to get a CVE number assigned.

http://mail-archives.apache.org/mod_mbox/subversion-dev/201407.mbox/%3C53DAB4A7.8030004%40reser.org%3E
Comment 4 Andreas Stieger 2014-08-01 16:35:16 UTC
(In reply to comment #1)
> does this have a CVE already? if not we would ask on oss-sec

http://seclists.org/oss-sec/2014/q3/275: CVE-2014-3528
Comment 5 Swamp Workflow Management 2014-08-01 22:00:12 UTC
bugbot adjusting priority
Comment 6 Bernhard Wiedemann 2014-08-11 20:00:43 UTC
This is an autogenerated message for OBS integration:
This bug (889849) was mentioned in
https://build.opensuse.org/request/show/244258 13.1+12.3 / libserf+subversion
Comment 10 Swamp Workflow Management 2014-08-15 10:02:42 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2014-08-29.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/58606
Comment 11 SMASH SMASH 2014-08-15 10:05:15 UTC
Affected packages:

SLE-11-SP2: subversion
SLE-11-SP3: subversion
Comment 14 Swamp Workflow Management 2014-08-23 00:04:44 UTC
openSUSE-SU-2014:1059-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 889849,890510,890511
CVE References: CVE-2014-3504,CVE-2014-3522,CVE-2014-3528
Sources used:
openSUSE 13.1 (src):    libserf-1.3.7-16.1, subversion-1.8.10-2.29.1
openSUSE 12.3 (src):    libserf-1.1.1-2.4.1, subversion-1.7.18-2.36.1
Comment 15 Swamp Workflow Management 2014-08-28 17:04:27 UTC
SUSE-SU-2014:1071-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 889849
CVE References: CVE-2014-3528
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    subversion-1.6.17-1.29.1
Comment 16 Marcus Meissner 2014-08-29 20:03:47 UTC
released
Comment 17 Swamp Workflow Management 2014-08-29 23:04:34 UTC
SUSE-SU-2014:1071-2: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 889849
CVE References: CVE-2014-3528
Sources used:
SUSE Studio Onsite 1.3 (src):    subversion-1.6.17-1.29.1