CVE-2011-1752
published 2011-06-06CVE-2011-1752: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service…
PriorityP271medium5CVSS 2.0
AVNACLAuNCNINAP
ITWVulnCheck KEV
Exploited in the wild
EPSS
8.48%
94.4th percentile
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | < 1.6.17 | 1.6.17 |
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.6.17dfsg-1 | 1.6.17dfsg-1 |
| apache | subversion | >= 0 < 1.6.17dfsg-1 | 1.6.17dfsg-1 |
| apache | subversion | >= 0 < 1.6.17dfsg-1 | 1.6.17dfsg-1 |
| apache | subversion | >= 0 < 1.6.17dfsg-1 | 1.6.17dfsg-1 |
| apple | mac_os_x | < 10.7.3 | 10.7.3 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | subversion | < subversion 1.6.17dfsg-1 (bookworm) | subversion 1.6.17dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect requests targeting baselined WebDAV resources against mod_dav_svn; a NULL pointer dereference in the httpd child process results in a crash, indicating exploitation. ↗
- →Monitor Apache httpd child process crashes (NULL pointer dereference / daemon crash) coinciding with WebDAV requests to Subversion repositories, particularly requests for baselined WebDAV resources. ↗
- →Vulnerable versions are Apache Subversion 1.0.0 through 1.6.16 with mod_dav_svn enabled; flag any such deployment receiving unexpected WebDAV REPORT or OPTIONS requests referencing baseline resources. ↗
- ·The vulnerability only affects Apache Subversion installations using the mod_dav_svn module for Apache HTTP Server; standalone svnserve deployments are not affected. ↗
- ·This vulnerability was actively exploited in the wild as of May 2011; treat any unpatched mod_dav_svn instance (versions 1.0.0–1.6.16) as actively at risk. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vulncheck5.0MEDIUM
vendor_apache5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jg5g-xghx-3fqc: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1
ghsa_unreviewed·2022-05-13
CVE-2011-1752 [MEDIUM] CWE-476 GHSA-jg5g-xghx-3fqc: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.
OSV
CVE-2011-1752: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1
osv·2011-06-06·CVSS 5.0
CVE-2011-1752 [MEDIUM] CVE-2011-1752: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.
VulnCheck
Apache subversion NULL Pointer Dereference
vulncheck·2011·CVSS 5.0
CVE-2011-1752 [MEDIUM] Apache subversion NULL Pointer Dereference
Apache subversion NULL Pointer Dereference
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.
Affected: Apache subversion
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://subversion.apache.org/security/CVE-2011-1752-advisory.txt; https://www.cve.org/CVERecord?id=CVE-2011-1752
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2011-06-06·CVSS 5.0
CVE-2011-1752 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: An attacker could send crafted input to the Subversion mod_dav_svn module
for Apache and cause it to crash or gain access to restricted files.
Joe Schaefer discovered that the Subversion mod_dav_svn module for Apache
did not properly handle certain baselined WebDAV resource requests. A
remote attacker could use this flaw to cause the service to crash, leading
to a denial of service. (CVE-2011-1752)
Ivan Zhakov discovered that the Subversion mod_dav_svn module for Apache
did not properly handle certain requests. A remote attacker could use this
flaw to cause the service to consume all available resources, leading to a
denial of service. (CVE-2011-1783)
Kamesh Jayachandran discovered that the Subversion mod_dav_svn module for
Apache did not prop
Red Hat
(mod_dav_svn): DoS (crash) via request to deliver baselined WebDAV resources
vendor_redhat·2011-06-01·CVSS 5.0
CVE-2011-1752 [MEDIUM] (mod_dav_svn): DoS (crash) via request to deliver baselined WebDAV resources
(mod_dav_svn): DoS (crash) via request to deliver baselined WebDAV resources
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.
Debian
CVE-2011-1752: subversion - The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subv...
vendor_debian·2011·CVSS 5.0
CVE-2011-1752 [MEDIUM] CVE-2011-1752: subversion - The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subv...
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.
Scope: local
bookworm: resolved (fixed in 1.6.17dfsg-1)
bullseye: resolved (fixed in 1.6.17dfsg-1)
forky: resolved (fixed in 1.6.17dfsg-1)
sid: resolved (fixed in 1.6.17dfsg-1)
trixie: resolved (fixed in 1.6.17dfsg-1)
Apache
Apache subversion: CVE-2011-1752
vendor_apache·CVSS 5.0
CVE-2011-1752 [MEDIUM] Apache subversion: CVE-2011-1752
Apache subversion: CVE-2011-1752
-advisory.txt 1.0.0-1.6.16 Server NULL-pointer dereference
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1752 CVE-2011-1783 CVE-2011-1921 subversion various flaws [fedora-all]
bugzilla·2011-06-02·CVSS 5.0
CVE-2011-1752 [MEDIUM] CVE-2011-1752 CVE-2011-1783 CVE-2011-1921 subversion various flaws [fedora-all]
CVE-2011-1752 CVE-2011-1783 CVE-2011-1921 subversion various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=709111
Please note: this issue affects mul
Bugzilla
CVE-2011-1752 subversion (mod_dav_svn): DoS (crash) via request to deliver baselined WebDAV resources
bugzilla·2011-05-30·CVSS 5.0
CVE-2011-1752 [MEDIUM] CVE-2011-1752 subversion (mod_dav_svn): DoS (crash) via request to deliver baselined WebDAV resources
CVE-2011-1752 subversion (mod_dav_svn): DoS (crash) via request to deliver baselined WebDAV resources
A NULL pointer dereference flaw was found in the way mod_dav_svn module
of the subversion concurrent version control system processed requests
submitted against the URL of a baselined resource. A remote attacker
could use this flaw to cause the httpd child process to crash.
Acknowledgements:
Red Hat would like to thank the Apache Subversion project for reporting this
issue. Upstream acknowledges Joe Schaefer of Apache Software Foundation as the
original reporter.
Discussion:
This issue affects the versions of the subversion package, as shipped
with Red Hat Enterprise Linux 4, 5, and 6.
--
This issue affects the versions of the subversion package, as shipped
with Fedora release of 13
http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/062211.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061913.htmlhttp://secunia.com/advisories/44633http://secunia.com/advisories/44681http://secunia.com/advisories/44849http://secunia.com/advisories/44879http://secunia.com/advisories/44888http://secunia.com/advisories/45162http://subversion.apache.org/security/CVE-2011-1752-advisory.txthttp://support.apple.com/kb/HT5130http://svn.apache.org/repos/asf/subversion/tags/1.6.17/CHANGEShttp://www.debian.org/security/2011/dsa-2251http://www.mandriva.com/security/advisories?name=MDVSA-2011:106http://www.redhat.com/support/errata/RHSA-2011-0861.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0862.htmlhttp://www.securityfocus.com/bid/48091http://www.securitytracker.com/id?1025617http://www.ubuntu.com/usn/USN-1144-1https://bugzilla.redhat.com/show_bug.cgi?id=709111https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18922http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/062211.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061913.htmlhttp://secunia.com/advisories/44633http://secunia.com/advisories/44681http://secunia.com/advisories/44849http://secunia.com/advisories/44879http://secunia.com/advisories/44888http://secunia.com/advisories/45162http://subversion.apache.org/security/CVE-2011-1752-advisory.txthttp://support.apple.com/kb/HT5130http://svn.apache.org/repos/asf/subversion/tags/1.6.17/CHANGEShttp://www.debian.org/security/2011/dsa-2251http://www.mandriva.com/security/advisories?name=MDVSA-2011:106http://www.redhat.com/support/errata/RHSA-2011-0861.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0862.htmlhttp://www.securityfocus.com/bid/48091http://www.securitytracker.com/id?1025617http://www.ubuntu.com/usn/USN-1144-1https://bugzilla.redhat.com/show_bug.cgi?id=709111https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18922
2011-06-06
Published
Exploited in the wild