PT-2011-3364 · Apache+1 · Apache Subversion+1

Published

2011-06-06

·

Updated

2024-06-15

·

CVE-2011-1783

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache Subversion versions 1.5.x through 1.6.16
Description The issue allows remote attackers to cause a denial of service, resulting in an infinite loop and memory consumption, under certain circumstances when the SVNPathAuthz short circuit option is enabled. This can be triggered by requesting specific data.
Recommendations For Apache Subversion versions 1.5.x through 1.6.16, consider disabling the SVNPathAuthz short circuit option as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2011-1783
DSA-2251-1
OPENSUSE-SU-2024:10538-1
RHSA-2011:0862
RHSA-2011_0862

Affected Products

Apache Subversion
Red Hat