cbcvebase.
CVE-2011-1783
published 2011-06-06

CVE-2011-1783: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit…

PriorityP424medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
6.74%
93.2th percentile
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data.

Affected

16 ranges
VendorProductVersion rangeFixed in
apachesubversion
apachesubversion>= 0 < 1.6.17dfsg-11.6.17dfsg-1
apachesubversion>= 0 < 1.6.17dfsg-11.6.17dfsg-1
apachesubversion>= 0 < 1.6.17dfsg-11.6.17dfsg-1
apachesubversion>= 0 < 1.6.17dfsg-11.6.17dfsg-1
apachesubversion1.5.0 – 1.5.8
apachesubversion>= 1.6.0 < 1.6.171.6.17
applemac_os_x< 10.7.310.7.3
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiansubversion< subversion 1.6.17dfsg-1 (bookworm)subversion 1.6.17dfsg-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_ubuntu5.0MEDIUM
vendor_apache4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.