You are viewing a plain text version of this content. The canonical link for it is here.
Posted to announce@apache.org by Troy Curtis <tr...@apache.org> on 2019/01/23 03:55:14 UTC
[CVE-2018-11803] Apache Subversion Denial of Service Vulnerability
This is a security notification for Apache Subversion HTTP Servers:
CVE-2018-11803
Severity: Medium
Affected Versions: Apache Subversion 1.11.0, 1.10.0 to 1.10.3
Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0
to 1.10.3 will crash after dereferencing an uninitialized pointer if the
client omits the root path in a recursive directory listing operation.
This issue can be triggered by any client on Subversion repositories
configured for anonymous read access. If read access requires
authentication, a denial of service attack can only be performed by an
authenticated user.
The Subversion releases 1.10.4 and 1.11.1 contain the fixes for this
vulnerability and are available immediately at:
https://dist.apache.org/repos/dist/release/subversion/?p=32084
Additional details, including patches for 1.10.3 and 1.11.0 can be found at:
https://subversion.apache.org/security/CVE-2018-11803-advisory.txt
We encourage users of Subversion to upgrade to the latest appropriate
version as soon as reasonable.
Thanks,
- The Subversion Team
Re: [CVE-2018-11803] Apache Subversion Denial of Service Vulnerability
Posted by Troy Curtis Jr <tr...@gmail.com>.
On Thu, Jan 24, 2019 at 2:17 PM Julian Foad <ju...@apache.org> wrote:
>
> Thanks, Troy.
>
> I have noted this CVE fix in the CHANGES file in r1852014 and pushed it to 1.10 and 1.11 branches so people looking there can find it.
>
Thanks Julian! That was on my TODO list, but didn't get to it last
night. I also wasn't sure about the whole modifying the release
branches, etc. So this is perfect!
Troy
> --
> - Julian
Re: [CVE-2018-11803] Apache Subversion Denial of Service Vulnerability
Posted by Julian Foad <ju...@apache.org>.
Thanks, Troy.
I have noted this CVE fix in the CHANGES file in r1852014 and pushed it to 1.10 and 1.11 branches so people looking there can find it.
--
- Julian
Re: [CVE-2018-11803] Apache Subversion Denial of Service
Vulnerability
Posted by Stefan Sperling <st...@stsp.name>.
On Wed, Jan 23, 2019 at 07:31:40PM +0000, Daniel Shahaf wrote:
> Thanks for all the work taking care of this, Troy!
Big +1 in large friendly letters!
Re: [CVE-2018-11803] Apache Subversion Denial of Service Vulnerability
Posted by Daniel Shahaf <d....@daniel.shahaf.name>.
Thanks for all the work taking care of this, Troy!
Troy Curtis wrote on Tue, 22 Jan 2019 22:55 -0500:
> This is a security notification for Apache Subversion HTTP Servers:
>
> CVE-2018-11803
> Severity: Medium
> Affected Versions: Apache Subversion 1.11.0, 1.10.0 to 1.10.3