Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade subversion | Feb 5, 2019 | Feb 5, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 5, 2019 |
| Debian | — | Upgrade subversion | Jul 30, 2024 | Feb 5, 2019 |
| Gentoo Linux | — | Upgrade dev-vcs/subversion. | Apr 3, 2019 | Feb 5, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade subversionUpgrade subversion-libsUpgrade mod_dav_svn | Jul 26, 2019 | Feb 5, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 5, 2019 |
| Suse | — | Upgrade subversion-pythonUpgrade libsvn_auth_kwallet-1-0Upgrade subversion-python-ctypesUpgrade subversion-bash-completionUpgrade subversion-develUpgrade subversion-perlUpgrade subversionUpgrade subversion-serverUpgrade libsvn_auth_gnome_keyring-1-0Upgrade subversion-rubyUpgrade subversion-tools | Feb 9, 2019 | Jan 24, 2019 |
| Ubuntu | — | Upgrade libsvn1Upgrade libapache2-mod-svnUpgrade subversion | Feb 1, 2019 | Jan 24, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 5, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub