3.5
CVSSv2

CVE-2013-4558

Published: 07/12/2013 Updated: 28/03/2024
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P

Vulnerability Summary

The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 up to and including 1.7.13 and 1.8.1 up to and including 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote malicious users to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request, as demonstrated using a trailing /.

Vulnerable Product Search on Vulmon Subscribe to Product

apache subversion 1.8.2

apache subversion 1.7.11

apache subversion 1.8.1

apache subversion 1.7.12

apache mod dav svn -

apache subversion 1.7.13

apache subversion 1.8.4

apache subversion 1.8.3

Vendor Advisories

Debian Bug report logs - #730541 subversion: CVE-2013-4505 Package: subversion; Maintainer for subversion is James McCoy <jamessan@debianorg>; Source for subversion is src:subversion (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Tue, 26 Nov 2013 11:06:02 UTC Severity: normal Tags: pen ...
The is_this_legal function in mod_dontdothat for Apache Subversion 140 through 1713 and 180 through 184 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL in a REPORT request The get_parent_resource function in reposc in mod_dav_svn Apache HTTPD s ...
The get_parent_resource function in reposc in mod_dav_svn Apache HTTPD server module in Subversion 1711 through 1713 and 181 through 184, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request ...