[3.9] subversion: malicious SVN clients can crash mod_dav_svn (CVE-2018-11803)ID: oval:org.secpod.oval:def:1801362 | Date: (C)2019-04-29 (M)2023-11-10 |
Class: PATCH | Family: unix |
Subversion 1.10.0 introduced server-side support for recursive directory listing operations. The implementation in mod_dav_svn failed to validate the root path of the directory listing provided by the client. If the client omits the root path, mod_dav_svn will deference an uninitialized pointer variable and crash the HTTPD worker process handling the request. Fixed In Version:¶ subversion 1.10.4, subversion 1.11.1
Platform: |
Alpine Linux 3.9 |