PT-2019-1346 · Apache+2 · Apache Subversion+2

Ivan Zhakov

·

Publicado

2019-01-18

·

Atualizado

2024-06-15

·

CVE-2018-11803

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Subversion mod dav svn module versions 1.10.0 through 1.10.3 Apache Subversion mod dav svn module version 1.11.0
Description The issue is related to a pointer dereference error in the mod dav svn module of Apache Subversion. This can be exploited by a remote attacker to cause a denial of service. The vulnerability occurs when a client omits the root path in a recursive directory listing operation, causing the module to crash after dereferencing an uninitialized pointer.
Recommendations For version 1.10.0 through 1.10.3, update to a version that fixes the pointer dereference error to prevent denial of service attacks. For version 1.11.0, update to a version that fixes the pointer dereference error to prevent denial of service attacks. As a temporary workaround, consider restricting access to the recursive directory listing operation to minimize the risk of exploitation.

Correção

NULL Pointer Dereference

Access of Uninitialized Pointer

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-00684
CVE-2018-11803
OPENSUSE-SU-2019:0153-1
OPENSUSE-SU-2019_0153-1
OPENSUSE-SU-2024:11412-1
SUSE-SU-2019:0195-1
SUSE-SU-2019_0195-1
USN-3869-1

Produtos afetados

Apache Subversion
Suse
Ubuntu