[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248585

 
 

909

 
 

195621

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-0032Date: (C)2014-02-14   (M)2023-12-22


The get_resource function in repos.c in the mod_dav_svn module in Apache Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is enabled, allows remote attackers to cause a denial of service (crash) via vectors related to the server root and request methods other than GET, as demonstrated by the "svn ls http://svn.example.com" command.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
OSVDB-102927
SECUNIA-56822
SECUNIA-60722
SECUNIA-61321
BID-65434
GLSA-201610-05
RHSA-2014:0255
USN-2316-1
http://mail-archives.apache.org/mod_mbox/subversion-dev/201401.mbox/%3C52D328AB.8090502%40reser.org%3E
http://mail-archives.apache.org/mod_mbox/subversion-dev/201401.mbox/%3C871u0gqb0d.fsf%40ntlworld.com%3E
http://mail-archives.apache.org/mod_mbox/subversion-dev/201401.mbox/%3CCANvU9scLHr2yOLABW8q6_wNzhEf7pWM=NiavGcobqvUuyhKyAA%40mail.gmail.com%3E
apache-subversion-cve20140032-dos(90986)
http://support.apple.com/kb/HT6444
http://svn.apache.org/repos/asf/subversion/tags/1.7.15/CHANGES
http://svn.apache.org/repos/asf/subversion/tags/1.8.6/CHANGES
http://svn.apache.org/viewvc?view=revision&revision=1557320
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
openSUSE-SU-2014:0307
openSUSE-SU-2014:0334

CPE    21
cpe:/a:apache:subversion
cpe:/a:apache:subversion:1.7.11
cpe:/a:apache:subversion:1.7.0
cpe:/a:apache:subversion:1.7.12
...
CWE    1
CWE-20
OVAL    13
oval:org.secpod.oval:def:106544
oval:org.secpod.oval:def:17040
oval:org.secpod.oval:def:1600007
oval:org.secpod.oval:def:1300285
...

© SecPod Technologies