[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-4558Date: (C)2013-12-09   (M)2024-04-04


The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request, as demonstrated using a trailing /.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 3.5
Exploit Score: 6.8
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: SINGLE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
OSVDB-100363
http://subversion.apache.org/security/CVE-2013-4558-advisory.txt
https://bugzilla.redhat.com/show_bug.cgi?id=1033431
https://github.com/apache/subversion/commit/2c77c43e4255555f3b79f761f0d141393a3856cc
https://github.com/apache/subversion/commit/647e3f8365a74831bb915f63793b63e31fae062d
openSUSE-SU-2013:1836
openSUSE-SU-2013:1860

CWE    1
CWE-20
OVAL    6
oval:org.secpod.oval:def:106177
oval:org.secpod.oval:def:16223
oval:org.secpod.oval:def:106260
oval:org.secpod.oval:def:1300255
...

© SecPod Technologies