[CVE-2018-11803] Apache Subversion Denial of Service Vulnerability

classic Classic list List threaded Threaded
5 messages Options
Reply | Threaded
Open this post in threaded view
|

[CVE-2018-11803] Apache Subversion Denial of Service Vulnerability

Troy Curtis Jr-2
This is a security notification for Apache Subversion HTTP Servers:

CVE-2018-11803
Severity: Medium
Affected Versions: Apache Subversion 1.11.0, 1.10.0 to 1.10.3

Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0
to 1.10.3 will crash after dereferencing an uninitialized pointer if the
client omits the root path in a recursive directory listing operation.
This issue can be triggered by any client on Subversion repositories
configured for anonymous read access. If read access requires
authentication, a denial of service attack can only be performed by an
authenticated user.

The Subversion releases 1.10.4 and 1.11.1 contain the fixes for this
vulnerability and are available immediately at:

https://dist.apache.org/repos/dist/release/subversion/?p=32084

Additional details, including patches for 1.10.3 and 1.11.0 can be found at:

https://subversion.apache.org/security/CVE-2018-11803-advisory.txt

We encourage users of Subversion to upgrade to the latest appropriate
version as soon as reasonable.

Thanks,
- The Subversion Team
Reply | Threaded
Open this post in threaded view
|

Re: [CVE-2018-11803] Apache Subversion Denial of Service Vulnerability

Daniel Shahaf-2
Thanks for all the work taking care of this, Troy!

Troy Curtis wrote on Tue, 22 Jan 2019 22:55 -0500:
> This is a security notification for Apache Subversion HTTP Servers:
>
> CVE-2018-11803
> Severity: Medium
> Affected Versions: Apache Subversion 1.11.0, 1.10.0 to 1.10.3
Reply | Threaded
Open this post in threaded view
|

Re: [CVE-2018-11803] Apache Subversion Denial of Service Vulnerability

Stefan Sperling-5
On Wed, Jan 23, 2019 at 07:31:40PM +0000, Daniel Shahaf wrote:
> Thanks for all the work taking care of this, Troy!

Big +1 in large friendly letters!
Reply | Threaded
Open this post in threaded view
|

Re: [CVE-2018-11803] Apache Subversion Denial of Service Vulnerability

Julian Foad-5
Thanks, Troy.

I have noted this CVE fix in the CHANGES file in r1852014 and pushed it to 1.10 and 1.11 branches so people looking there can find it.

--
- Julian
Reply | Threaded
Open this post in threaded view
|

Re: [CVE-2018-11803] Apache Subversion Denial of Service Vulnerability

Troy Curtis Jr
On Thu, Jan 24, 2019 at 2:17 PM Julian Foad <[hidden email]> wrote:
>
> Thanks, Troy.
>
> I have noted this CVE fix in the CHANGES file in r1852014 and pushed it to 1.10 and 1.11 branches so people looking there can find it.
>

Thanks Julian! That was on my TODO list, but didn't get to it last
night. I also wasn't sure about the whole modifying the release
branches, etc. So this is perfect!

Troy

> --
> - Julian