You are viewing a plain text version of this content. The canonical link for it is here.
Posted to announce@apache.org by Troy Curtis <tr...@apache.org> on 2019/01/23 03:55:14 UTC

[CVE-2018-11803] Apache Subversion Denial of Service Vulnerability

This is a security notification for Apache Subversion HTTP Servers:

CVE-2018-11803
Severity: Medium
Affected Versions: Apache Subversion 1.11.0, 1.10.0 to 1.10.3

Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 
to 1.10.3 will crash after dereferencing an uninitialized pointer if the 
client omits the root path in a recursive directory listing operation. 
This issue can be triggered by any client on Subversion repositories 
configured for anonymous read access. If read access requires 
authentication, a denial of service attack can only be performed by an 
authenticated user.

The Subversion releases 1.10.4 and 1.11.1 contain the fixes for this 
vulnerability and are available immediately at:

https://dist.apache.org/repos/dist/release/subversion/?p=32084

Additional details, including patches for 1.10.3 and 1.11.0 can be found at:

https://subversion.apache.org/security/CVE-2018-11803-advisory.txt

We encourage users of Subversion to upgrade to the latest appropriate 
version as soon as reasonable.

Thanks,
- The Subversion Team

Re: [CVE-2018-11803] Apache Subversion Denial of Service Vulnerability

Posted by Troy Curtis Jr <tr...@gmail.com>.
On Thu, Jan 24, 2019 at 2:17 PM Julian Foad <ju...@apache.org> wrote:
>
> Thanks, Troy.
>
> I have noted this CVE fix in the CHANGES file in r1852014 and pushed it to 1.10 and 1.11 branches so people looking there can find it.
>

Thanks Julian! That was on my TODO list, but didn't get to it last
night. I also wasn't sure about the whole modifying the release
branches, etc. So this is perfect!

Troy

> --
> - Julian

Re: [CVE-2018-11803] Apache Subversion Denial of Service Vulnerability

Posted by Julian Foad <ju...@apache.org>.
Thanks, Troy.

I have noted this CVE fix in the CHANGES file in r1852014 and pushed it to 1.10 and 1.11 branches so people looking there can find it.

-- 
- Julian

Re: [CVE-2018-11803] Apache Subversion Denial of Service Vulnerability

Posted by Stefan Sperling <st...@stsp.name>.
On Wed, Jan 23, 2019 at 07:31:40PM +0000, Daniel Shahaf wrote:
> Thanks for all the work taking care of this, Troy!

Big +1 in large friendly letters!

Re: [CVE-2018-11803] Apache Subversion Denial of Service Vulnerability

Posted by Daniel Shahaf <d....@daniel.shahaf.name>.
Thanks for all the work taking care of this, Troy!

Troy Curtis wrote on Tue, 22 Jan 2019 22:55 -0500:
> This is a security notification for Apache Subversion HTTP Servers:
> 
> CVE-2018-11803
> Severity: Medium
> Affected Versions: Apache Subversion 1.11.0, 1.10.0 to 1.10.3