Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade subversion | Feb 5, 2019 | Feb 5, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 5, 2019 |
| Debian | — | Upgrade subversion | Jul 30, 2024 | Feb 5, 2019 |
| Gentoo Linux | — | Upgrade dev-vcs/subversion. | Apr 3, 2019 | Feb 5, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade subversionUpgrade subversion-libsUpgrade mod_dav_svn | Jul 26, 2019 | Feb 5, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 5, 2019 |
| Suse | — | Upgrade subversion-python-ctypesUpgrade libsvn_auth_kwallet-1-0Upgrade subversion-pythonUpgrade subversion-bash-completionUpgrade subversionUpgrade subversion-perlUpgrade subversion-toolsUpgrade subversion-serverUpgrade libsvn_auth_gnome_keyring-1-0Upgrade subversion-develUpgrade subversion-ruby | Feb 9, 2019 | Jan 24, 2019 |
| Ubuntu | — | Upgrade subversionUpgrade libapache2-mod-svnUpgrade libsvn1 | Feb 1, 2019 | Jan 24, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 5, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub