CVE-2011-0715
published 2011-03-11CVE-2011-0715: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service…
PriorityP423medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
6.31%
92.9th percentile
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.
Affected
118 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | <= 1.6.15 | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_apache4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerability
vendor_ubuntu·2011-03-29
CVE-2011-0715 Subversion vulnerability
Title: Subversion vulnerability
Summary: An attacker could send crafted input to the Subversion mod_dav_svn module
for Apache and cause it to crash.
Philip Martin discovered that the Subversion mod_dav_svn module for Apache
did not properly handle certain requests containing a lock token. A remote
attacker could use this flaw to cause the service to crash, leading to a
denial of service.
Instructions: After a standard system update you need to restart any applications that
use Subversion, such as Apache when using mod_dav_svn, to make all the
necessary changes.
Red Hat
(mod_dav_svn): DoS (NULL ptr deref) by a lock token sent from a not authenticated Subversion client
vendor_redhat·2011-03-03·CVSS 4.3
CVE-2011-0715 [MEDIUM] (mod_dav_svn): DoS (NULL ptr deref) by a lock token sent from a not authenticated Subversion client
(mod_dav_svn): DoS (NULL ptr deref) by a lock token sent from a not authenticated Subversion client
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.
Package: subversion (Red Hat Enterprise Linux 4) - Not affected
Debian
CVE-2011-0715: subversion - The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subv...
vendor_debian·2011·CVSS 4.3
CVE-2011-0715 [MEDIUM] CVE-2011-0715: subversion - The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subv...
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.
Scope: local
bookworm: resolved (fixed in 1.6.16dfsg-1)
bullseye: resolved (fixed in 1.6.16dfsg-1)
forky: resolved (fixed in 1.6.16dfsg-1)
sid: resolved (fixed in 1.6.16dfsg-1)
trixie: resolved (fixed in 1.6.16dfsg-1)
Apache
Apache subversion: CVE-2011-0715
vendor_apache·CVSS 4.3
CVE-2011-0715 [MEDIUM] Apache subversion: CVE-2011-0715
Apache subversion: CVE-2011-0715
-advisory.txt 1.2.0-1.5.9, 1.6.0-1.6.15 Server NULL-pointer dereference
GHSA
GHSA-gvp9-hg34-593w: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1
ghsa_unreviewed·2022-05-17
CVE-2011-0715 [MEDIUM] GHSA-gvp9-hg34-593w: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.
OSV
CVE-2011-0715: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1
osv·2011-03-11·CVSS 4.3
CVE-2011-0715 [MEDIUM] CVE-2011-0715: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-0715 subversion (mod_dav_svn): DoS (NULL ptr deref) by a lock token sent from a not authenticated Subversion client [fedora-all]
bugzilla·2011-03-08·CVSS 4.3
CVE-2011-0715 [MEDIUM] CVE-2011-0715 subversion (mod_dav_svn): DoS (NULL ptr deref) by a lock token sent from a not authenticated Subversion client [fedora-all]
CVE-2011-0715 subversion (mod_dav_svn): DoS (NULL ptr deref) by a lock token sent from a not authenticated Subversion client [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_
Bugzilla
CVE-2011-0715 subversion (mod_dav_svn): DoS (NULL ptr deref) by a lock token sent from a not authenticated Subversion client
bugzilla·2011-02-27·CVSS 4.3
CVE-2011-0715 [MEDIUM] CVE-2011-0715 subversion (mod_dav_svn): DoS (NULL ptr deref) by a lock token sent from a not authenticated Subversion client
CVE-2011-0715 subversion (mod_dav_svn): DoS (NULL ptr deref) by a lock token sent from a not authenticated Subversion client
A NULL pointer dereference flaw was found in the way mod_dav_svn,
Apache httpd module for Subversion server, processed requests to
lock working copy paths in the repository, when particular Subversion
client, requesting the lock, was not previously authenticated to
the Subversion server. A remote attacker could use this flaw
to cause a denial of service (crash of particular httpd thread,
serving the request).
Acknowledgements:
Red Hat would like to thank Hyrum Wright of the Apache Subversion project
for reporting this issue. Upstream acknowledges Philip Martin, WANdisco, Inc. as the original reporter.
Discussion:
This issue did NOT affect the version of the subv
http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056071.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056072.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056736.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://secunia.com/advisories/43583http://secunia.com/advisories/43603http://secunia.com/advisories/43672http://secunia.com/advisories/43794http://securitytracker.com/id?1025161http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.479953http://subversion.apache.org/security/CVE-2011-0715-advisory.txthttp://support.apple.com/kb/HT4723http://svn.apache.org/repos/asf/subversion/tags/1.6.16/CHANGEShttp://svn.apache.org/viewvc?view=revision&revision=1071239http://svn.apache.org/viewvc?view=revision&revision=1071307http://svn.haxx.se/dev/archive-2011-03/0122.shtmlhttp://www.debian.org/security/2011/dsa-2181http://www.mandriva.com/security/advisories?name=MDVSA-2011:067http://www.osvdb.org/70964http://www.securityfocus.com/bid/46734http://www.ubuntu.com/usn/USN-1096-1http://www.vupen.com/english/advisories/2011/0567http://www.vupen.com/english/advisories/2011/0568http://www.vupen.com/english/advisories/2011/0624http://www.vupen.com/english/advisories/2011/0660http://www.vupen.com/english/advisories/2011/0684http://www.vupen.com/english/advisories/2011/0776http://www.vupen.com/english/advisories/2011/0885https://bugzilla.redhat.com/show_bug.cgi?id=680755https://exchange.xforce.ibmcloud.com/vulnerabilities/65876https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18967https://rhn.redhat.com/errata/RHSA-2011-0327.htmlhttps://rhn.redhat.com/errata/RHSA-2011-0328.htmlhttp://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056071.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056072.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/056736.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://secunia.com/advisories/43583http://secunia.com/advisories/43603http://secunia.com/advisories/43672http://secunia.com/advisories/43794http://securitytracker.com/id?1025161http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.479953http://subversion.apache.org/security/CVE-2011-0715-advisory.txthttp://support.apple.com/kb/HT4723http://svn.apache.org/repos/asf/subversion/tags/1.6.16/CHANGEShttp://svn.apache.org/viewvc?view=revision&revision=1071239http://svn.apache.org/viewvc?view=revision&revision=1071307http://svn.haxx.se/dev/archive-2011-03/0122.shtmlhttp://www.debian.org/security/2011/dsa-2181http://www.mandriva.com/security/advisories?name=MDVSA-2011:067http://www.osvdb.org/70964http://www.securityfocus.com/bid/46734http://www.ubuntu.com/usn/USN-1096-1http://www.vupen.com/english/advisories/2011/0567http://www.vupen.com/english/advisories/2011/0568http://www.vupen.com/english/advisories/2011/0624http://www.vupen.com/english/advisories/2011/0660http://www.vupen.com/english/advisories/2011/0684http://www.vupen.com/english/advisories/2011/0776http://www.vupen.com/english/advisories/2011/0885https://bugzilla.redhat.com/show_bug.cgi?id=680755https://exchange.xforce.ibmcloud.com/vulnerabilities/65876https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18967https://rhn.redhat.com/errata/RHSA-2011-0327.htmlhttps://rhn.redhat.com/errata/RHSA-2011-0328.html
2011-03-11
Published