CVE-2014-3522
Summary
| CVE | CVE-2014-3522 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-08-19 18:55:02 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:H/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Subversion | 1.4.0 | All | All | All |
| Application | Apache | Subversion | 1.4.1 | All | All | All |
| Application | Apache | Subversion | 1.4.2 | All | All | All |
| Application | Apache | Subversion | 1.4.3 | All | All | All |
| Application | Apache | Subversion | 1.4.4 | All | All | All |
| Application | Apache | Subversion | 1.4.5 | All | All | All |
| Application | Apache | Subversion | 1.4.6 | All | All | All |
| Application | Apache | Subversion | 1.5.0 | All | All | All |
| Application | Apache | Subversion | 1.5.1 | All | All | All |
| Application | Apache | Subversion | 1.5.2 | All | All | All |
| Application | Apache | Subversion | 1.5.3 | All | All | All |
| Application | Apache | Subversion | 1.5.4 | All | All | All |
| Application | Apache | Subversion | 1.5.5 | All | All | All |
| Application | Apache | Subversion | 1.5.6 | All | All | All |
| Application | Apache | Subversion | 1.5.7 | All | All | All |
| Application | Apache | Subversion | 1.5.8 | All | All | All |
| Application | Apache | Subversion | 1.6.0 | All | All | All |
| Application | Apache | Subversion | 1.6.1 | All | All | All |
| Application | Apache | Subversion | 1.6.10 | All | All | All |
| Application | Apache | Subversion | 1.6.11 | All | All | All |
| Application | Apache | Subversion | 1.6.12 | All | All | All |
| Application | Apache | Subversion | 1.6.13 | All | All | All |
| Application | Apache | Subversion | 1.6.14 | All | All | All |
| Application | Apache | Subversion | 1.6.15 | All | All | All |
| Application | Apache | Subversion | 1.6.16 | All | All | All |
| Application | Apache | Subversion | 1.6.17 | All | All | All |
| Application | Apache | Subversion | 1.6.18 | All | All | All |
| Application | Apache | Subversion | 1.6.19 | All | All | All |
| Application | Apache | Subversion | 1.6.2 | All | All | All |
| Application | Apache | Subversion | 1.6.20 | All | All | All |
| Application | Apache | Subversion | 1.6.21 | All | All | All |
| Application | Apache | Subversion | 1.6.23 | All | All | All |
| Application | Apache | Subversion | 1.6.3 | All | All | All |
| Application | Apache | Subversion | 1.6.4 | All | All | All |
| Application | Apache | Subversion | 1.6.5 | All | All | All |
| Application | Apache | Subversion | 1.6.6 | All | All | All |
| Application | Apache | Subversion | 1.6.7 | All | All | All |
| Application | Apache | Subversion | 1.6.8 | All | All | All |
| Application | Apache | Subversion | 1.6.9 | All | All | All |
| Application | Apache | Subversion | 1.7.0 | All | All | All |
| Application | Apache | Subversion | 1.7.1 | All | All | All |
| Application | Apache | Subversion | 1.7.10 | All | All | All |
| Application | Apache | Subversion | 1.7.11 | All | All | All |
| Application | Apache | Subversion | 1.7.12 | All | All | All |
| Application | Apache | Subversion | 1.7.13 | All | All | All |
| Application | Apache | Subversion | 1.7.14 | All | All | All |
| Application | Apache | Subversion | 1.7.15 | All | All | All |
| Application | Apache | Subversion | 1.7.16 | All | All | All |
| Application | Apache | Subversion | 1.7.17 | All | All | All |
| Application | Apache | Subversion | 1.7.2 | All | All | All |
| Application | Apache | Subversion | 1.7.3 | All | All | All |
| Application | Apache | Subversion | 1.7.4 | All | All | All |
| Application | Apache | Subversion | 1.7.5 | All | All | All |
| Application | Apache | Subversion | 1.7.6 | All | All | All |
| Application | Apache | Subversion | 1.7.7 | All | All | All |
| Application | Apache | Subversion | 1.7.8 | All | All | All |
| Application | Apache | Subversion | 1.7.9 | All | All | All |
| Application | Apache | Subversion | 1.8.0 | All | All | All |
| Application | Apache | Subversion | 1.8.1 | All | All | All |
| Application | Apache | Subversion | 1.8.2 | All | All | All |
| Application | Apache | Subversion | 1.8.3 | All | All | All |
| Application | Apache | Subversion | 1.8.4 | All | All | All |
| Application | Apache | Subversion | 1.8.5 | All | All | All |
| Application | Apache | Subversion | 1.8.6 | All | All | All |
| Application | Apache | Subversion | 1.8.7 | All | All | All |
| Application | Apache | Subversion | 1.8.8 | All | All | All |
| Application | Apache | Subversion | 1.8.9 | All | All | All |
| Application | Apple | Xcode | 6.1.1 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 12.04 | - | lts | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Opensuse | Opensuse | 12.3 | All | All | All |
| Operating System | Opensuse | Opensuse | 13.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory SA60722 - Ubuntu update for subversion - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Apache Subversion CVE-2014-3522 SSL Certificate Validation Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| APPLE-SA-2015-03-09-4 Xcode 6.2 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Mailing List, Third Party Advisory |
| Security Advisory SA59432 - Ubuntu update for subversion - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| subversion.apache.org/security/CVE-2014-3522-advisory.txt | af854a3a-2127-422b-91ae-364da2661108 | subversion.apache.org | Patch, Vendor Advisory |
| Oracle Solaris Third Party Bulletin - October 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Security Advisory SA59584 - SUSE update for libserf and subversion - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Subversion, Serf: Multiple Vulnerabilities (GLSA 201610-05) — Gentoo Security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| www.osvdb.org/109996 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| USN-2316-1: Subversion vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| openSUSE-SU-2014:1059-1: moderate: update for libserf, subversion | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory |
| About the security content of Xcode 6.2 - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.