Apache · Apache Subversion · CVE-2018-11782
**Name of the Vulnerable Software and Affected Versions**
Apache Subversion versions up to and including 1.9.10
Apache Subversion versions up to and including 1.10.4
Apache Subversion versions up to and including 1.12.0
**Description**
The issue arises due to insufficient input validation in the svnserve server process of the Subversion centralized version control system. This can be exploited by a remote attacker to cause a denial of service, disrupting the server's operation. When a well-formed read-only request produces a particular answer, the Subversion's svnserve server process may exit, leading to disruption for users of the server.
**Recommendations**
For Apache Subversion version 1.9.10, update to a version later than 1.9.10 to resolve the issue.
For Apache Subversion version 1.10.4, update to a version later than 1.10.4 to resolve the issue.
For Apache Subversion version 1.12.0, update to a version later than 1.12.0 to resolve the issue.