CVE-2010-4644
published 2011-01-07CVE-2010-4644: Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and…
PriorityP415low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
4.46%
90.4th percentile
Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.
Affected
117 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | <= 1.6.14 | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv3.5LOW
vendor_apache3.5LOW
vendor_debian3.5LOW
vendor_redhat3.5LOW
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2011-02-01·CVSS 2.1
CVE-2007-2448 [LOW] Subversion vulnerabilities
Title: Subversion vulnerabilities
It was discovered that Subversion incorrectly handled certain 'partial
access' privileges in rare scenarios. Remote authenticated users could use
this flaw to obtain sensitive information (revision properties). This issue
only applied to Ubuntu 6.06 LTS. (CVE-2007-2448)
It was discovered that the Subversion mod_dav_svn module for Apache did not
properly handle a named repository as a rule scope. Remote authenticated
users could use this flaw to bypass intended restrictions. This issue only
applied to Ubuntu 9.10, 10.04 LTS, and 10.10. (CVE-2010-3315)
It was discovered that the Subversion mod_dav_svn module for Apache
incorrectly handled the walk function. Remote authenticated users could use
this flaw to cause the service to crash, leading to a denial o
Red Hat
Subversion: DoS (memory consumption) by processing blame or log -g requests on certain files
vendor_redhat·2010-11-04·CVSS 3.5
CVE-2010-4644 [LOW] Subversion: DoS (memory consumption) by processing blame or log -g requests on certain files
Subversion: DoS (memory consumption) by processing blame or log -g requests on certain files
Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.
Package: subversion (Red Hat Enterprise Linux 4) - Not affected
Debian
CVE-2010-4644: subversion - Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow rem...
vendor_debian·2010·CVSS 3.5
CVE-2010-4644 [LOW] CVE-2010-4644: subversion - Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow rem...
Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.
Scope: local
bookworm: resolved (fixed in 1.6.12dfsg-3)
bullseye: resolved (fixed in 1.6.12dfsg-3)
forky: resolved (fixed in 1.6.12dfsg-3)
sid: resolved (fixed in 1.6.12dfsg-3)
trixie: resolved (fixed in 1.6.12dfsg-3)
Apache
Apache subversion: CVE-2010-4644
vendor_apache·CVSS 3.5
CVE-2010-4644 [LOW] Apache subversion: CVE-2010-4644
Apache subversion: CVE-2010-4644
1.5.0-1.5.8, 1.6.0-1.6.13 Server out-of-memory error caused by 'blame -g'
GHSA
GHSA-hhpj-h4jc-w378: Multiple memory leaks in rev_hunt
ghsa_unreviewed·2022-05-17
CVE-2010-4644 [LOW] GHSA-hhpj-h4jc-w378: Multiple memory leaks in rev_hunt
Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.
OSV
CVE-2010-4644: Multiple memory leaks in rev_hunt
osv·2011-01-07·CVSS 3.5
CVE-2010-4644 [LOW] CVE-2010-4644: Multiple memory leaks in rev_hunt
Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4644 Subversion: DoS (memory consumption) by processing blame or log -g requests on certain files
bugzilla·2011-01-06·CVSS 3.5
CVE-2010-4644 [LOW] CVE-2010-4644 Subversion: DoS (memory consumption) by processing blame or log -g requests on certain files
CVE-2010-4644 Subversion: DoS (memory consumption) by processing blame or log -g requests on certain files
A server-side memory leak in Subversion before v1.6.15
allowed remote attackers to cause a denial of service
(memory consumption and daemon outage or crash) via
Subversion client "blame" or "log" operations performed
on certain repository files, when the -g option (request
to display additional merge history for the file) was used.
References:
[1] http://svn.haxx.se/dev/archive-2010-11/0102.shtml
[2] http://svn.apache.org/repos/asf/subversion/tags/1.6.15/CHANGES
Upstream changeset:
[3] http://svn.apache.org/viewvc?view=revision&revision=1032808
Public PoC:
[4] http://svn.haxx.se/dev/archive-2010-11/0163.shtml
Discussion:
This issue did not affect the versions of the subversion p
Bugzilla
CVE-2010-4539 CVE-2010-4644 subversion various flaws [fedora-13]
bugzilla·2011-01-06·CVSS 6.8
CVE-2010-4539 [MEDIUM] CVE-2010-4539 CVE-2010-4644 subversion various flaws [fedora-13]
CVE-2010-4539 CVE-2010-4644 subversion various flaws [fedora-13]
fedora-13 tracking bug for subversion: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-4644
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=667407,667763
---
subversion-1.6.15-1.fc13 has been submitted as an update for Fedora 13.
https://admin.fedoraproject.org/updates/subversion-1.6.15-1.fc13
---
subversion-1.6.15-1.fc13 has been pushed to the Fedora 13 testing repository. If problems still persist, please make note of it in this bug report.
If you want to test the update, you can
Bugzilla
CVE-2010-1455 wireshark: DOCSIS dissector crash
bugzilla·2010-05-10·CVSS 4.3
CVE-2010-1455 [MEDIUM] CVE-2010-1455 wireshark: DOCSIS dissector crash
CVE-2010-1455 wireshark: DOCSIS dissector crash
Upstream wireshark versions 1.0.13 and 1.2.8 fix a flaw in the DOCSIS dissector. This dissector used incorrect format string specified when printing certain values (%s was used to print numeric values, causing numeric value to be used as pointer), which could cause wireshark to crash or create garbaged output.
Upstream advisories:
1.0.13 http://www.wireshark.org/security/wnpa-sec-2010-03.html
1.2.8 http://www.wireshark.org/security/wnpa-sec-2010-04.html
Upstream bug reports:
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4644
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4646
Upstream commits:
http://anonsvn.wireshark.org/viewvc?view=rev&revision=32396
http://anonsvn.wireshark.org/viewvc?view=rev&revision=32398
http://anonsvn.w
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053230.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-users/201011.mbox/%3C4CD33B61.7030203%40thepond.com%3Ehttp://mail-archives.apache.org/mod_mbox/www-announce/201011.mbox/%3CAANLkTi=5+NOi-Cp=fKCx6mAW-TofFVW=ikEQkXgQB8Bt%40mail.gmail.com%3Ehttp://openwall.com/lists/oss-security/2011/01/02/1http://openwall.com/lists/oss-security/2011/01/04/10http://openwall.com/lists/oss-security/2011/01/04/8http://openwall.com/lists/oss-security/2011/01/05/4http://secunia.com/advisories/42780http://secunia.com/advisories/42969http://secunia.com/advisories/43115http://secunia.com/advisories/43139http://secunia.com/advisories/43346http://svn.apache.org/repos/asf/subversion/tags/1.6.15/CHANGEShttp://svn.apache.org/viewvc?view=revision&revision=1032808http://svn.haxx.se/dev/archive-2010-11/0102.shtmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:006http://www.redhat.com/support/errata/RHSA-2011-0257.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0258.htmlhttp://www.securityfocus.com/bid/45655http://www.securitytracker.com/id?1024935http://www.ubuntu.com/usn/USN-1053-1http://www.vupen.com/english/advisories/2011/0015http://www.vupen.com/english/advisories/2011/0103http://www.vupen.com/english/advisories/2011/0162http://www.vupen.com/english/advisories/2011/0264https://exchange.xforce.ibmcloud.com/vulnerabilities/64473http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053230.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-users/201011.mbox/%3C4CD33B61.7030203%40thepond.com%3Ehttp://mail-archives.apache.org/mod_mbox/www-announce/201011.mbox/%3CAANLkTi=5+NOi-Cp=fKCx6mAW-TofFVW=ikEQkXgQB8Bt%40mail.gmail.com%3Ehttp://openwall.com/lists/oss-security/2011/01/02/1http://openwall.com/lists/oss-security/2011/01/04/10http://openwall.com/lists/oss-security/2011/01/04/8http://openwall.com/lists/oss-security/2011/01/05/4http://secunia.com/advisories/42780http://secunia.com/advisories/42969http://secunia.com/advisories/43115http://secunia.com/advisories/43139http://secunia.com/advisories/43346http://svn.apache.org/repos/asf/subversion/tags/1.6.15/CHANGEShttp://svn.apache.org/viewvc?view=revision&revision=1032808http://svn.haxx.se/dev/archive-2010-11/0102.shtmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:006http://www.redhat.com/support/errata/RHSA-2011-0257.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0258.htmlhttp://www.securityfocus.com/bid/45655http://www.securitytracker.com/id?1024935http://www.ubuntu.com/usn/USN-1053-1http://www.vupen.com/english/advisories/2011/0015http://www.vupen.com/english/advisories/2011/0103http://www.vupen.com/english/advisories/2011/0162http://www.vupen.com/english/advisories/2011/0264https://exchange.xforce.ibmcloud.com/vulnerabilities/64473
2011-01-07
Published