CVE-2013-1847
published 2013-05-02CVE-2013-1847: The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service…
PriorityP340medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
51.44%
98.8th percentile
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an anonymous LOCK for a URL that does not exist.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect anonymous HTTP LOCK requests targeting non-existent repository URLs on mod_dav_svn-enabled Apache servers; such requests require no authentication and will trigger a NULL pointer dereference crash. ↗
- →Monitor Apache HTTPD access/error logs for HTTP LOCK method requests returning 5xx errors or causing process crashes on SVN DAV endpoints. ↗
- →Flag HTTP LOCK method requests from unauthenticated (anonymous) clients against DAV/SVN repository paths as suspicious; legitimate LOCK usage typically requires authentication. ↗
- ·Vulnerable versions are Subversion 1.6.0–1.6.20 and 1.7.0–1.7.8 only; mod_dav_svn must be loaded in Apache HTTPD for the attack surface to exist. ↗
- ·The vulnerability is exploitable only when authentication is NOT required for the LOCK method on the targeted SVN path or activity URL. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_apache5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu2.1LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2013-06-27·CVSS 2.1
CVE-2013-1845 [LOW] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in Subversion.
Alexander Klink discovered that the Subversion mod_dav_svn module for
Apache did not properly handle a large number of properties. A remote
authenticated attacker could use this flaw to cause memory consumption,
leading to a denial of service. (CVE-2013-1845)
Ben Reser discovered that the Subversion mod_dav_svn module for
Apache did not properly handle certain LOCKs. A remote authenticated
attacker could use this flaw to cause Subversion to crash, leading to a
denial of service. (CVE-2013-1846)
Philip Martin and Ben Reser discovered that the Subversion mod_dav_svn
module for Apache did not properly handle certain LOCKs. A remote
attacker could use this flaw to cause Subversion to crash, leading
Red Hat
(mod_dav_svn): DoS (crash) via LOCK requests against a non-existent URL
vendor_redhat·2013-04-04·CVSS 5.0
CVE-2013-1847 [MEDIUM] (mod_dav_svn): DoS (crash) via LOCK requests against a non-existent URL
(mod_dav_svn): DoS (crash) via LOCK requests against a non-existent URL
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an anonymous LOCK for a URL that does not exist.
Debian
CVE-2013-1847: subversion - The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 an...
vendor_debian·2013·CVSS 5.0
CVE-2013-1847 [MEDIUM] CVE-2013-1847: subversion - The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 an...
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an anonymous LOCK for a URL that does not exist.
Scope: local
bookworm: resolved (fixed in 1.7.9-1)
bullseye: resolved (fixed in 1.7.9-1)
forky: resolved (fixed in 1.7.9-1)
sid: resolved (fixed in 1.7.9-1)
trixie: resolved (fixed in 1.7.9-1)
Apache
Apache subversion: CVE-2013-1847
vendor_apache·CVSS 5.0
CVE-2013-1847 [MEDIUM] Apache subversion: CVE-2013-1847
Apache subversion: CVE-2013-1847
-advisory.txt 1.6.0-1.6.20 and 1.7.0-1.7.8 mod_dav_svn crashes on LOCK requests against non-existant URLs
GHSA
GHSA-2c79-3xrg-7c85: The mod_dav_svn Apache HTTPD server module in Subversion 1
ghsa_unreviewed·2022-05-17
CVE-2013-1847 [MEDIUM] GHSA-2c79-3xrg-7c85: The mod_dav_svn Apache HTTPD server module in Subversion 1
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an anonymous LOCK for a URL that does not exist.
OSV
CVE-2013-1847: The mod_dav_svn Apache HTTPD server module in Subversion 1
osv·2013-05-02·CVSS 5.0
CVE-2013-1847 [MEDIUM] CVE-2013-1847: The mod_dav_svn Apache HTTPD server module in Subversion 1
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an anonymous LOCK for a URL that does not exist.
No detection rules found.
Bugzilla
CVE-2013-1845 CVE-2013-1846 CVE-2013-1847 CVE-2013-1849 CVE-2013-1884 subversion various flaws [fedora-all]
bugzilla·2013-04-05·CVSS 2.1
CVE-2013-1845 [LOW] CVE-2013-1845 CVE-2013-1846 CVE-2013-1847 CVE-2013-1849 CVE-2013-1884 subversion various flaws [fedora-all]
CVE-2013-1845 CVE-2013-1846 CVE-2013-1847 CVE-2013-1849 CVE-2013-1884 subversion various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available
Bugzilla
CVE-2013-1847 Subversion (mod_dav_svn): DoS (crash) via LOCK requests against a non-existent URL
bugzilla·2013-03-29·CVSS 5.0
CVE-2013-1847 [MEDIUM] CVE-2013-1847 Subversion (mod_dav_svn): DoS (crash) via LOCK requests against a non-existent URL
CVE-2013-1847 Subversion (mod_dav_svn): DoS (crash) via LOCK requests against a non-existent URL
It was found that Subversion's mod_dav_svn Apache HTTPD server module will crash in some circumstances when a LOCK request is made against a non-existent URL. This can lead to DoS.
The vulnerability can be triggered by doing a LOCK request against a URL for a path that does not exist in the repository or an invalid activity URL where authentication is not required for the LOCK method.
Acknowledgements:
Red Hat would like to thank the Apache Subversion project for reporting this issue. Upstream acknowledges Philip Martin and Ben Reser as the original reporter of this flaw.
Discussion:
Created attachment 717972
patch-against-1.6.20
---
Created attachment 717973
patch-against-1.7.8
---
T
http://lists.opensuse.org/opensuse-updates/2013-04/msg00095.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00069.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-announce/201304.mbox/%3CCADkdwvRoyVrZV12tgC0FMGrc6%2BMisd3qTcZ%2BDdpFGgTahkgAkQ%40mail.gmail.com%3Ehttp://mail-archives.apache.org/mod_mbox/subversion-announce/201304.mbox/%3CCADkdwvSTMLbn4q_KM3Ph2UOeSiPGhEK4%3DSvwEjaHW_GUGkYWPQ%40mail.gmail.com%3Ehttp://rhn.redhat.com/errata/RHSA-2013-0737.htmlhttp://subversion.apache.org/security/CVE-2013-1847-advisory.txthttp://www.mandriva.com/security/advisories?name=MDVSA-2013:153http://www.ubuntu.com/usn/USN-1893-1https://bugzilla.redhat.com/show_bug.cgi?id=929090https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18538http://lists.opensuse.org/opensuse-updates/2013-04/msg00095.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00069.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-announce/201304.mbox/%3CCADkdwvRoyVrZV12tgC0FMGrc6%2BMisd3qTcZ%2BDdpFGgTahkgAkQ%40mail.gmail.com%3Ehttp://mail-archives.apache.org/mod_mbox/subversion-announce/201304.mbox/%3CCADkdwvSTMLbn4q_KM3Ph2UOeSiPGhEK4%3DSvwEjaHW_GUGkYWPQ%40mail.gmail.com%3Ehttp://rhn.redhat.com/errata/RHSA-2013-0737.htmlhttp://subversion.apache.org/security/CVE-2013-1847-advisory.txthttp://www.mandriva.com/security/advisories?name=MDVSA-2013:153http://www.ubuntu.com/usn/USN-1893-1https://bugzilla.redhat.com/show_bug.cgi?id=929090https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18538
2013-05-02
Published