PT-2013-5073 · Apache+1 · Subversion+1

Philip Martin

·

Published

2013-11-30

·

Updated

2024-06-15

·

CVE-2013-4558

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Subversion versions 1.7.11 through 1.7.13 Subversion versions 1.8.1 through 1.8.4
Description The issue allows remote attackers to cause a denial of service, resulting in an assertion failure and Apache process abort, via a non-canonical URL in a request. This can be demonstrated using a trailing /. The problem occurs when the get parent resource function in repos.c is used with assertions enabled and SVNAutoversioning is enabled.
Recommendations For Subversion versions 1.7.11 through 1.7.13, consider disabling SVNAutoversioning to minimize the risk of exploitation until a patch is available. For Subversion versions 1.8.1 through 1.8.4, consider disabling SVNAutoversioning to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider restricting access to non-canonical URLs to prevent the denial of service.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4558
MGASA-2013-0360
OPENSUSE-SU-2024:10538-1
SUSE-SU-2015:0709-1

Affected Products

Subversion
Suse