5
CVSSv2

CVE-2013-1884

Published: 02/05/2013 Updated: 19/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 up to and including 1.7.8 allows remote malicious users to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variable.

Vulnerable Product Search on Vulmon Subscribe to Product

apache subversion 1.7.0

apache subversion 1.7.7

apache subversion 1.7.5

apache subversion 1.7.6

apache subversion 1.7.3

apache subversion 1.7.4

apache subversion 1.7.1

apache subversion 1.7.2

Vendor Advisories

Debian Bug report logs - #704940 subversion: cve-2013-1845 cve-2013-1846 cve-2013-1847 cve-2013-1849 cve-2013-1884 Package: src:subversion; Maintainer for src:subversion is James McCoy <jamessan@debianorg>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Mon, 8 Apr 2013 00:27:01 UTC Severity: serious Tags: ...
Several security issues were fixed in Subversion ...
The mod_dav_svn Apache HTTPD server module in Subversion 170 through 178 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variable ...

Exploits

source: wwwsecurityfocuscom/bid/58898/info Apache Subversion is prone to a remote denial-of-service vulnerability Attackers can exploit this issue to crash the application, resulting in denial-of-service conditions Apache Subversion versions 170 through 178 are vulnerable curl -X REPORT --data-binary @log_report 'wwwexa ...