PT-2013-5073 · Apache+1 · Subversion+1

Philip Martin

·

Publicado

2013-11-30

·

Atualizado

2024-06-15

·

CVE-2013-4558

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Subversion versions 1.7.11 through 1.7.13 Subversion versions 1.8.1 through 1.8.4
Description The issue allows remote attackers to cause a denial of service, resulting in an assertion failure and Apache process abort, via a non-canonical URL in a request. This can be demonstrated using a trailing /. The problem occurs when the get parent resource function in repos.c is used with assertions enabled and SVNAutoversioning is enabled.
Recommendations For Subversion versions 1.7.11 through 1.7.13, consider disabling SVNAutoversioning to minimize the risk of exploitation until a patch is available. For Subversion versions 1.8.1 through 1.8.4, consider disabling SVNAutoversioning to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider restricting access to non-canonical URLs to prevent the denial of service.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-4558
MGASA-2013-0360
OPENSUSE-SU-2024:10538-1
SUSE-SU-2015:0709-1

Produtos afetados

Subversion
Suse