CVE-2013-1849
published 2013-05-02CVE-2013-1849: The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service…
PriorityP425medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
8.85%
94.6th percentile
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_apache4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2013-06-27·CVSS 2.1
CVE-2013-1845 [LOW] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in Subversion.
Alexander Klink discovered that the Subversion mod_dav_svn module for
Apache did not properly handle a large number of properties. A remote
authenticated attacker could use this flaw to cause memory consumption,
leading to a denial of service. (CVE-2013-1845)
Ben Reser discovered that the Subversion mod_dav_svn module for
Apache did not properly handle certain LOCKs. A remote authenticated
attacker could use this flaw to cause Subversion to crash, leading to a
denial of service. (CVE-2013-1846)
Philip Martin and Ben Reser discovered that the Subversion mod_dav_svn
module for Apache did not properly handle certain LOCKs. A remote
attacker could use this flaw to cause Subversion to crash, leading
Red Hat
(mod_dav_svn): DoS (crash) via PROPFIND request made against activity URLs
vendor_redhat·2013-03-05·CVSS 4.3
CVE-2013-1849 [MEDIUM] (mod_dav_svn): DoS (crash) via PROPFIND request made against activity URLs
(mod_dav_svn): DoS (crash) via PROPFIND request made against activity URLs
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.
Debian
CVE-2013-1849: subversion - The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 an...
vendor_debian·2013·CVSS 4.3
CVE-2013-1849 [MEDIUM] CVE-2013-1849: subversion - The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 an...
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.
Scope: local
bookworm: resolved (fixed in 1.7.9-1)
bullseye: resolved (fixed in 1.7.9-1)
forky: resolved (fixed in 1.7.9-1)
sid: resolved (fixed in 1.7.9-1)
trixie: resolved (fixed in 1.7.9-1)
Apache
Apache subversion: CVE-2013-1849
vendor_apache·CVSS 4.3
CVE-2013-1849 [MEDIUM] Apache subversion: CVE-2013-1849
Apache subversion: CVE-2013-1849
-advisory.txt 1.0.0-1.6.20 and 1.7.0-1.7.8 mod_dav_svn crashes on PROPFIND requests against activity URLs
GHSA
GHSA-7xgj-rr5f-9wv9: The mod_dav_svn Apache HTTPD server module in Subversion 1
ghsa_unreviewed·2022-05-17
CVE-2013-1849 [MEDIUM] GHSA-7xgj-rr5f-9wv9: The mod_dav_svn Apache HTTPD server module in Subversion 1
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.
OSV
CVE-2013-1849: The mod_dav_svn Apache HTTPD server module in Subversion 1
osv·2013-05-02·CVSS 4.3
CVE-2013-1849 [MEDIUM] CVE-2013-1849: The mod_dav_svn Apache HTTPD server module in Subversion 1
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.
No detection rules found.
Bugzilla
CVE-2013-1845 CVE-2013-1846 CVE-2013-1847 CVE-2013-1849 CVE-2013-1884 subversion various flaws [fedora-all]
bugzilla·2013-04-05·CVSS 2.1
CVE-2013-1845 [LOW] CVE-2013-1845 CVE-2013-1846 CVE-2013-1847 CVE-2013-1849 CVE-2013-1884 subversion various flaws [fedora-all]
CVE-2013-1845 CVE-2013-1846 CVE-2013-1847 CVE-2013-1849 CVE-2013-1884 subversion various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available
Bugzilla
CVE-2013-1849 Subversion (mod_dav_svn): DoS (crash) via PROPFIND request made against activity URLs
bugzilla·2013-03-29·CVSS 4.3
CVE-2013-1849 [MEDIUM] CVE-2013-1849 Subversion (mod_dav_svn): DoS (crash) via PROPFIND request made against activity URLs
CVE-2013-1849 Subversion (mod_dav_svn): DoS (crash) via PROPFIND request made against activity URLs
It was found that Subversion's mod_dav_svn Apache HTTPD server module will crash when a PROPFIND request is made against activity URLs. This can lead to a DoS.
There is a flaw in mod_dav_svn that improperly tries to process this request instead of rejecting it and results in an attempt to access invalid memory (NULL). Which results in the httpd process segfaulting and dying. How bad the impact of that is varies based upon the configuration of the httpd server. httpd servers using a prefork MPM will simply start a new process to replace the process that died. Servers using threaded MPMs may be processing other requests in the same process as the process that the attack causes to die. In eit
http://lists.opensuse.org/opensuse-updates/2013-04/msg00095.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00069.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-announce/201304.mbox/%3CCADkdwvRoyVrZV12tgC0FMGrc6%2BMisd3qTcZ%2BDdpFGgTahkgAkQ%40mail.gmail.com%3Ehttp://mail-archives.apache.org/mod_mbox/subversion-announce/201304.mbox/%3CCADkdwvSTMLbn4q_KM3Ph2UOeSiPGhEK4%3DSvwEjaHW_GUGkYWPQ%40mail.gmail.com%3Ehttp://rhn.redhat.com/errata/RHSA-2013-0737.htmlhttp://seclists.org/fulldisclosure/2013/Mar/56http://subversion.apache.org/security/CVE-2013-1849-advisory.txthttp://www.mandriva.com/security/advisories?name=MDVSA-2013:153http://www.ubuntu.com/usn/USN-1893-1https://bugzilla.redhat.com/show_bug.cgi?id=929093https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18980http://lists.opensuse.org/opensuse-updates/2013-04/msg00095.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00069.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-announce/201304.mbox/%3CCADkdwvRoyVrZV12tgC0FMGrc6%2BMisd3qTcZ%2BDdpFGgTahkgAkQ%40mail.gmail.com%3Ehttp://mail-archives.apache.org/mod_mbox/subversion-announce/201304.mbox/%3CCADkdwvSTMLbn4q_KM3Ph2UOeSiPGhEK4%3DSvwEjaHW_GUGkYWPQ%40mail.gmail.com%3Ehttp://rhn.redhat.com/errata/RHSA-2013-0737.htmlhttp://seclists.org/fulldisclosure/2013/Mar/56http://subversion.apache.org/security/CVE-2013-1849-advisory.txthttp://www.mandriva.com/security/advisories?name=MDVSA-2013:153http://www.ubuntu.com/usn/USN-1893-1https://bugzilla.redhat.com/show_bug.cgi?id=929093https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18980
2013-05-02
Published