cbcvebase.
CVE-2011-1783
published 2011-06-06

CVE-2011-1783: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit…

medium4.3CVSS 3.1
AVNACMAuNCNINAP
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data.

Affected

16 ranges
VendorProductVersion rangeFixed in
apachesubversion
apachesubversion>= 0 < 1.6.17dfsg-11.6.17dfsg-1
apachesubversion>= 0 < 1.6.17dfsg-11.6.17dfsg-1
apachesubversion>= 0 < 1.6.17dfsg-11.6.17dfsg-1
apachesubversion>= 0 < 1.6.17dfsg-11.6.17dfsg-1
apachesubversion1.5.0 – 1.5.8
apachesubversion>= 1.6.0 < 1.6.171.6.17
applemac_os_x< 10.7.310.7.3
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiansubversion< subversion 1.6.17dfsg-1 (bookworm)subversion 1.6.17dfsg-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora

CVSS provenance

nvd4.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM