Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 518716 (CVE-2014-3528) - <dev-vcs/subversion-1.8.16: credentials leak via MD5 collision
Summary: <dev-vcs/subversion-1.8.16: credentials leak via MD5 collision
Status: RESOLVED FIXED
Alias: CVE-2014-3528
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [glsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-08-01 07:23 UTC by Agostino Sarubbo
Modified: 2016-10-11 12:47 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-08-01 07:23:42 UTC
From ${URL} :

A possible MD5 collision issue was found in the way Subversion handled cached credentials. If an 
attacker could trick a victim into connecting to their Subversion server, they could send a 
specially-crafted realm string to the victim that could trigger an MD5 collision. This could lead 
to the Subversion client sending another realm's credentials to the attacker's server.

Upstream patches:

http://svn.apache.org/r1550691
http://svn.apache.org/r1550772

References:

http://mail-archives.apache.org/mod_mbox/subversion-dev/201406.mbox/%3C53915FD8.7050600@reser.org%3E


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2016-07-18 10:27:38 UTC
(In reply to Agostino Sarubbo from comment #0)
> From ${URL} :
> 
> A possible MD5 collision issue was found in the way Subversion handled
> cached credentials. If an 
> attacker could trick a victim into connecting to their Subversion server,
> they could send a 
> specially-crafted realm string to the victim that could trigger an MD5
> collision. This could lead 
> to the Subversion client sending another realm's credentials to the
> attacker's server.
> 
> Upstream patches:
> 
> http://svn.apache.org/r1550691
> http://svn.apache.org/r1550772

Full patchset present in >=dev-vcs/subversion-1.8.16. 

Added to existing GLSA.
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2016-10-11 12:47:07 UTC
This issue was resolved and addressed in
 GLSA 201610-05 at https://security.gentoo.org/glsa/201610-05
by GLSA coordinator Aaron Bauman (b-man).