CVE-2015-0251
EPSS 1.1%
Description
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.
How to fix CVE-2015-0251
To remediate CVE-2015-0251, upgrade the affected package to a fixed version below.
- Debian/subversion—upgrade to 1.8.10-6 or later
Is CVE-2015-0251 being exploited?
Low — EPSS is 1.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.8.10-6