CVE-2011-1783
published 2011-06-06CVE-2011-1783: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit…
PriorityP424medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
6.74%
93.2th percentile
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.6.17dfsg-1 | 1.6.17dfsg-1 |
| apache | subversion | >= 0 < 1.6.17dfsg-1 | 1.6.17dfsg-1 |
| apache | subversion | >= 0 < 1.6.17dfsg-1 | 1.6.17dfsg-1 |
| apache | subversion | >= 0 < 1.6.17dfsg-1 | 1.6.17dfsg-1 |
| apache | subversion | 1.5.0 – 1.5.8 | — |
| apache | subversion | >= 1.6.0 < 1.6.17 | 1.6.17 |
| apple | mac_os_x | < 10.7.3 | 10.7.3 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | subversion | < subversion 1.6.17dfsg-1 (bookworm) | subversion 1.6.17dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_ubuntu5.0MEDIUM
vendor_apache4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2011-06-06·CVSS 5.0
CVE-2011-1752 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: An attacker could send crafted input to the Subversion mod_dav_svn module
for Apache and cause it to crash or gain access to restricted files.
Joe Schaefer discovered that the Subversion mod_dav_svn module for Apache
did not properly handle certain baselined WebDAV resource requests. A
remote attacker could use this flaw to cause the service to crash, leading
to a denial of service. (CVE-2011-1752)
Ivan Zhakov discovered that the Subversion mod_dav_svn module for Apache
did not properly handle certain requests. A remote attacker could use this
flaw to cause the service to consume all available resources, leading to a
denial of service. (CVE-2011-1783)
Kamesh Jayachandran discovered that the Subversion mod_dav_svn module for
Apache did not prop
Red Hat
(mod_dav_svn): DoS (excessive memory use) when configured to provide path-based access control
vendor_redhat·2011-06-01·CVSS 4.3
CVE-2011-1783 [MEDIUM] (mod_dav_svn): DoS (excessive memory use) when configured to provide path-based access control
(mod_dav_svn): DoS (excessive memory use) when configured to provide path-based access control
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data.
Package: subversion (Red Hat Enterprise Linux 4) - Not affected
Debian
CVE-2011-1783: subversion - The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subv...
vendor_debian·2011·CVSS 4.3
CVE-2011-1783 [MEDIUM] CVE-2011-1783: subversion - The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subv...
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data.
Scope: local
bookworm: resolved (fixed in 1.6.17dfsg-1)
bullseye: resolved (fixed in 1.6.17dfsg-1)
forky: resolved (fixed in 1.6.17dfsg-1)
sid: resolved (fixed in 1.6.17dfsg-1)
trixie: resolved (fixed in 1.6.17dfsg-1)
Apache
Apache subversion: CVE-2011-1783
vendor_apache·CVSS 4.3
CVE-2011-1783 [MEDIUM] Apache subversion: CVE-2011-1783
Apache subversion: CVE-2011-1783
-advisory.txt 1.5.0-1.6.16 Server memory exhaustion
GHSA
GHSA-6hv5-jvfr-j4jm: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1
ghsa_unreviewed·2022-05-13
CVE-2011-1783 [MEDIUM] GHSA-6hv5-jvfr-j4jm: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data.
OSV
CVE-2011-1783: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1
osv·2011-06-06·CVSS 4.3
CVE-2011-1783 [MEDIUM] CVE-2011-1783: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1752 CVE-2011-1783 CVE-2011-1921 subversion various flaws [fedora-all]
bugzilla·2011-06-02·CVSS 5.0
CVE-2011-1752 [MEDIUM] CVE-2011-1752 CVE-2011-1783 CVE-2011-1921 subversion various flaws [fedora-all]
CVE-2011-1752 CVE-2011-1783 CVE-2011-1921 subversion various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=709111
Please note: this issue affects mul
Bugzilla
CVE-2011-1783 subversion (mod_dav_svn): DoS (excessive memory use) when configured to provide path-based access control
bugzilla·2011-05-30·CVSS 4.3
CVE-2011-1783 [MEDIUM] CVE-2011-1783 subversion (mod_dav_svn): DoS (excessive memory use) when configured to provide path-based access control
CVE-2011-1783 subversion (mod_dav_svn): DoS (excessive memory use) when configured to provide path-based access control
An infinite loop was found in the way mod_dav_svn module of the subversion
concurrent version control system processed certain data sets, when
SVNPathAuthz configuration directive with value of 'short_circuit' was used.
A remote attacker could use this flaw to cause the httpd child process to
consume excessive amount of system memory.
Acknowledgements:
Red Hat would like to thank the Apache Subversion project for reporting this
issue. Upstream acknowledges Ivan Zhakov of VisualSVN as the original reporter.
Discussion:
This issue did NOT affect the version of the subversion package, as shipped
with Red Hat Enterprise Linux 4.
--
This issue affects the versions of th
http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/062211.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061913.htmlhttp://secunia.com/advisories/44633http://secunia.com/advisories/44681http://secunia.com/advisories/44849http://secunia.com/advisories/44888http://secunia.com/advisories/45162http://subversion.apache.org/security/CVE-2011-1783-advisory.txthttp://support.apple.com/kb/HT5130http://svn.apache.org/repos/asf/subversion/tags/1.6.17/CHANGEShttp://www.debian.org/security/2011/dsa-2251http://www.mandriva.com/security/advisories?name=MDVSA-2011:106http://www.redhat.com/support/errata/RHSA-2011-0862.htmlhttp://www.securityfocus.com/bid/48091http://www.securitytracker.com/id?1025618http://www.ubuntu.com/usn/USN-1144-1https://bugzilla.redhat.com/show_bug.cgi?id=709112https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18889http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/062211.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061913.htmlhttp://secunia.com/advisories/44633http://secunia.com/advisories/44681http://secunia.com/advisories/44849http://secunia.com/advisories/44888http://secunia.com/advisories/45162http://subversion.apache.org/security/CVE-2011-1783-advisory.txthttp://support.apple.com/kb/HT5130http://svn.apache.org/repos/asf/subversion/tags/1.6.17/CHANGEShttp://www.debian.org/security/2011/dsa-2251http://www.mandriva.com/security/advisories?name=MDVSA-2011:106http://www.redhat.com/support/errata/RHSA-2011-0862.htmlhttp://www.securityfocus.com/bid/48091http://www.securitytracker.com/id?1025618http://www.ubuntu.com/usn/USN-1144-1https://bugzilla.redhat.com/show_bug.cgi?id=709112https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18889
2011-06-06
Published