Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade subversion | Feb 5, 2019 | Feb 5, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 5, 2019 |
| Debian | — | Upgrade subversion | Jul 30, 2024 | Feb 5, 2019 |
| Gentoo Linux | — | Upgrade dev-vcs/subversion. | Apr 3, 2019 | Feb 5, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade subversionUpgrade subversion-libsUpgrade mod_dav_svn | Jul 26, 2019 | Feb 5, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 5, 2019 |
| Suse | — | Upgrade subversion-bash-completionUpgrade libsvn_auth_kwallet-1-0Upgrade subversion-pythonUpgrade subversion-python-ctypesUpgrade libsvn_auth_gnome_keyring-1-0Upgrade subversion-serverUpgrade subversion-develUpgrade subversion-rubyUpgrade subversion-toolsUpgrade subversion-perlUpgrade subversion | Feb 9, 2019 | Jan 24, 2019 |
| Ubuntu | — | Upgrade libapache2-mod-svnUpgrade libsvn1Upgrade subversion | Feb 1, 2019 | Jan 24, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 5, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub