cbcvebase.
CVE-2011-1752
published 2011-06-06

CVE-2011-1752: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service…

PriorityP271medium5CVSS 2.0
AVNACLAuNCNINAP
ITWVulnCheck KEV
Exploited in the wild
EPSS
8.48%
94.4th percentile
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.

Affected

15 ranges
VendorProductVersion rangeFixed in
apachesubversion< 1.6.171.6.17
apachesubversion
apachesubversion>= 0 < 1.6.17dfsg-11.6.17dfsg-1
apachesubversion>= 0 < 1.6.17dfsg-11.6.17dfsg-1
apachesubversion>= 0 < 1.6.17dfsg-11.6.17dfsg-1
apachesubversion>= 0 < 1.6.17dfsg-11.6.17dfsg-1
applemac_os_x< 10.7.310.7.3
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiansubversion< subversion 1.6.17dfsg-1 (bookworm)subversion 1.6.17dfsg-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora

Detection & IOCsextracted from sources · hover to see the quote

urlhttp://subversion.apache.org/security/CVE-2011-1752-advisory.txt
  • Detect requests targeting baselined WebDAV resources against mod_dav_svn; a NULL pointer dereference in the httpd child process results in a crash, indicating exploitation.
  • Monitor Apache httpd child process crashes (NULL pointer dereference / daemon crash) coinciding with WebDAV requests to Subversion repositories, particularly requests for baselined WebDAV resources.
  • Vulnerable versions are Apache Subversion 1.0.0 through 1.6.16 with mod_dav_svn enabled; flag any such deployment receiving unexpected WebDAV REPORT or OPTIONS requests referencing baseline resources.
  • ·The vulnerability only affects Apache Subversion installations using the mod_dav_svn module for Apache HTTP Server; standalone svnserve deployments are not affected.
  • ·This vulnerability was actively exploited in the wild as of May 2011; treat any unpatched mod_dav_svn instance (versions 1.0.0–1.6.16) as actively at risk.

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vulncheck5.0MEDIUM
vendor_apache5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.