[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

[3.8] subversion: malicious SVN clients can crash mod_dav_svn (CVE-2018-11803)

ID: oval:org.secpod.oval:def:1801295Date: (C)2019-01-29   (M)2023-11-10
Class: PATCHFamily: unix




Subversion 1.10.0 introduced server-side support for recursive directory listing operations. The implementation in mod_dav_svn failed to validate the root path of the directory listing provided by the client. If the client omits the root path, mod_dav_svn will deference an uninitialized pointer variable and crash the HTTPD worker process handling the request. Fixed In Version:¶ subversion 1.10.4, subversion 1.11.1

Platform:
Alpine Linux 3.8
Product:
subversion
Reference:
9932
CVE-2018-11803
CVE    1
CVE-2018-11803
CPE    2
cpe:/a:apache:subversion
cpe:/o:alpinelinux:alpine_linux:3.8

© SecPod Technologies