2.6
CVSSv2

CVE-2013-4505

Published: 07/12/2013 Updated: 20/12/2013
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P

Vulnerability Summary

The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 up to and including 1.7.13 and 1.8.0 up to and including 1.8.4 allows remote malicious users to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL in a REPORT request.

Vulnerable Product Search on Vulmon Subscribe to Product

apache mod_dontdothat -

apache subversion 1.8.1

apache subversion 1.4.0

apache subversion 1.5.0

apache subversion 1.5.1

apache subversion 1.5.8

apache subversion 1.6.0

apache subversion 1.6.16

apache subversion 1.6.17

apache subversion 1.6.3

apache subversion 1.6.4

apache subversion 1.7.1

apache subversion 1.7.10

apache subversion 1.4.5

apache subversion 1.4.6

apache subversion 1.5.6

apache subversion 1.5.7

apache subversion 1.6.14

apache subversion 1.6.15

apache subversion 1.6.21

apache subversion 1.6.23

apache subversion 1.6.9

apache subversion 1.7.0

apache subversion 1.7.5

apache subversion 1.7.6

apache subversion 1.4.1

apache subversion 1.4.2

apache subversion 1.5.2

apache subversion 1.5.3

apache subversion 1.6.1

apache subversion 1.6.10

apache subversion 1.6.18

apache subversion 1.6.19

apache subversion 1.6.5

apache subversion 1.6.6

apache subversion 1.7.11

apache subversion 1.7.12

apache subversion 1.7.2

apache subversion 1.7.9

apache subversion 1.7.7

apache subversion 1.7.8

apache subversion 1.4.3

apache subversion 1.4.4

apache subversion 1.5.4

apache subversion 1.5.5

apache subversion 1.6.11

apache subversion 1.6.12

apache subversion 1.6.13

apache subversion 1.6.2

apache subversion 1.6.20

apache subversion 1.6.7

apache subversion 1.6.8

apache subversion 1.7.3

apache subversion 1.7.4

Vendor Advisories

Debian Bug report logs - #730541 subversion: CVE-2013-4505 Package: subversion; Maintainer for subversion is James McCoy <jamessan@debianorg>; Source for subversion is src:subversion (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Tue, 26 Nov 2013 11:06:02 UTC Severity: normal Tags: pen ...
The is_this_legal function in mod_dontdothat for Apache Subversion 140 through 1713 and 180 through 184 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL in a REPORT request The get_parent_resource function in reposc in mod_dav_svn Apache HTTPD s ...
The is_this_legal function in mod_dontdothat for Apache Subversion 140 through 1713 and 180 through 184 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL in a REPORT request ...