PT-2019-1346 · Apache+2 · Apache Subversion+2

Ivan Zhakov

·

Published

2019-01-18

·

Updated

2024-06-15

·

CVE-2018-11803

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Subversion mod dav svn module versions 1.10.0 through 1.10.3 Apache Subversion mod dav svn module version 1.11.0
Description The issue is related to a pointer dereference error in the mod dav svn module of Apache Subversion. This can be exploited by a remote attacker to cause a denial of service. The vulnerability occurs when a client omits the root path in a recursive directory listing operation, causing the module to crash after dereferencing an uninitialized pointer.
Recommendations For version 1.10.0 through 1.10.3, update to a version that fixes the pointer dereference error to prevent denial of service attacks. For version 1.11.0, update to a version that fixes the pointer dereference error to prevent denial of service attacks. As a temporary workaround, consider restricting access to the recursive directory listing operation to minimize the risk of exploitation.

Fix

NULL Pointer Dereference

Access of Uninitialized Pointer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00684
CVE-2018-11803
OPENSUSE-SU-2019:0153-1
OPENSUSE-SU-2019_0153-1
OPENSUSE-SU-2024:11412-1
SUSE-SU-2019:0195-1
SUSE-SU-2019_0195-1
USN-3869-1

Affected Products

Apache Subversion
Suse
Ubuntu