CVE-2013-1884
published 2013-05-02CVE-2013-1884: The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and…
PriorityP339medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
50.54%
98.8th percentile
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variable.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.7.9-1 | 1.7.9-1 |
| apache | subversion | >= 0 < 1.7.9-1 | 1.7.9-1 |
| apache | subversion | >= 0 < 1.7.9-1 | 1.7.9-1 |
| apache | subversion | >= 0 < 1.7.9-1 | 1.7.9-1 |
| debian | subversion | < subversion 1.7.9-1 (bookworm) | subversion 1.7.9-1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP REPORT method requests targeting SVN repository paths matching the pattern /!svn/bc/ — this is the attack vector for triggering the mod_dav_svn crash via an out-of-range limit in a log REPORT request. ↗
- →The vulnerability is triggered by a log REPORT request with an invalid (out of range) limit value sent to mod_dav_svn; monitor for HTTP REPORT requests with anomalous or non-numeric limit fields in the request body. ↗
- →The crash results in a segmentation fault in the Apache HTTPD process hosting mod_dav_svn; monitor for abnormal Apache worker process terminations (SIGSEGV) on SVN-serving hosts running Subversion 1.7.0–1.7.8. ↗
- ·Only Subversion versions 1.7.0 through 1.7.8 are vulnerable; versions 1.7.9 and later (including all current Fedora and Debian releases) are patched. Red Hat Enterprise Linux 5 and 6 ship a non-affected version. ↗
- ·The vulnerable component is specifically the mod_dav_svn Apache HTTPD server module; only servers with this module loaded and serving SVN repositories over HTTP/HTTPS are exposed. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_apache5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu2.1LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2013-06-27·CVSS 2.1
CVE-2013-1845 [LOW] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in Subversion.
Alexander Klink discovered that the Subversion mod_dav_svn module for
Apache did not properly handle a large number of properties. A remote
authenticated attacker could use this flaw to cause memory consumption,
leading to a denial of service. (CVE-2013-1845)
Ben Reser discovered that the Subversion mod_dav_svn module for
Apache did not properly handle certain LOCKs. A remote authenticated
attacker could use this flaw to cause Subversion to crash, leading to a
denial of service. (CVE-2013-1846)
Philip Martin and Ben Reser discovered that the Subversion mod_dav_svn
module for Apache did not properly handle certain LOCKs. A remote
attacker could use this flaw to cause Subversion to crash, leading
Red Hat
(mod_dav_svn): DoS (crash) via malformed log REPORT requests
vendor_redhat·2013-04-04·CVSS 5.0
CVE-2013-1884 [MEDIUM] (mod_dav_svn): DoS (crash) via malformed log REPORT requests
(mod_dav_svn): DoS (crash) via malformed log REPORT requests
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variable.
Statement: Not Vulnerable. This issue does not affect the version of subversion as shipped with Red Hat Enterprise Linux 5 and 6.
Package: subversion (Red Hat Enterprise Linux 5) - Not affected
Package: subversion (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2013-1884: subversion - The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 all...
vendor_debian·2013·CVSS 5.0
CVE-2013-1884 [MEDIUM] CVE-2013-1884: subversion - The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 all...
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variable.
Scope: local
bookworm: resolved (fixed in 1.7.9-1)
bullseye: resolved (fixed in 1.7.9-1)
forky: resolved (fixed in 1.7.9-1)
sid: resolved (fixed in 1.7.9-1)
trixie: resolved (fixed in 1.7.9-1)
Apache
Apache subversion: CVE-2013-1884
vendor_apache·CVSS 5.0
CVE-2013-1884 [MEDIUM] Apache subversion: CVE-2013-1884
Apache subversion: CVE-2013-1884
-advisory.txt 1.7.0-1.7.8 mod_dav_svn crashes on out of range limit in log REPORT request
GHSA
GHSA-chwm-g2mp-v6cv: The mod_dav_svn Apache HTTPD server module in Subversion 1
ghsa_unreviewed·2022-05-17
CVE-2013-1884 [MEDIUM] CWE-119 GHSA-chwm-g2mp-v6cv: The mod_dav_svn Apache HTTPD server module in Subversion 1
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variable.
OSV
CVE-2013-1884: The mod_dav_svn Apache HTTPD server module in Subversion 1
osv·2013-05-02·CVSS 5.0
CVE-2013-1884 [MEDIUM] CVE-2013-1884: The mod_dav_svn Apache HTTPD server module in Subversion 1
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variable.
No detection rules found.
Bugzilla
CVE-2013-1845 CVE-2013-1846 CVE-2013-1847 CVE-2013-1849 CVE-2013-1884 subversion various flaws [fedora-all]
bugzilla·2013-04-05·CVSS 2.1
CVE-2013-1845 [LOW] CVE-2013-1845 CVE-2013-1846 CVE-2013-1847 CVE-2013-1849 CVE-2013-1884 subversion various flaws [fedora-all]
CVE-2013-1845 CVE-2013-1846 CVE-2013-1847 CVE-2013-1849 CVE-2013-1884 subversion various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available
Bugzilla
CVE-2013-1884 Subversion (mod_dav_svn): DoS (crash) via malformed log REPORT requests
bugzilla·2013-03-29·CVSS 5.0
CVE-2013-1884 [MEDIUM] CVE-2013-1884 Subversion (mod_dav_svn): DoS (crash) via malformed log REPORT requests
CVE-2013-1884 Subversion (mod_dav_svn): DoS (crash) via malformed log REPORT requests
It was found that Subversion's mod_dav_svn Apache HTTPD server module will crash when a log REPORT request receives a limit that is out of the allowed range. This can lead to a DoS.
Acknowledgements:
Red Hat would like to thank the Apache Subversion for reporting this issue. Upstream acknowledges Greg McMullin, Stefan Fuhrmann, Philip Martin and Ben Reser as the original reporters of this flaw.
Discussion:
Created attachment 717976
patch
---
Statement:
Not Vulnerable. This issue does not affect the version of subversion as shipped with Red Hat Enterprise Linux 5 and 6.
---
External References:
http://subversion.apache.org/security/CVE-2013-1884-advisory.txt
---
Announcement:
http://mail-archi
http://lists.opensuse.org/opensuse-updates/2013-04/msg00095.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-announce/201304.mbox/%3CCADkdwvRoyVrZV12tgC0FMGrc6%2BMisd3qTcZ%2BDdpFGgTahkgAkQ%40mail.gmail.com%3Ehttp://subversion.apache.org/security/CVE-2013-1884-advisory.txthttp://www.mandriva.com/security/advisories?name=MDVSA-2013:153http://www.ubuntu.com/usn/USN-1893-1https://bugzilla.redhat.com/show_bug.cgi?id=929095https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18788http://lists.opensuse.org/opensuse-updates/2013-04/msg00095.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-announce/201304.mbox/%3CCADkdwvRoyVrZV12tgC0FMGrc6%2BMisd3qTcZ%2BDdpFGgTahkgAkQ%40mail.gmail.com%3Ehttp://subversion.apache.org/security/CVE-2013-1884-advisory.txthttp://www.mandriva.com/security/advisories?name=MDVSA-2013:153http://www.ubuntu.com/usn/USN-1893-1https://bugzilla.redhat.com/show_bug.cgi?id=929095https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18788
2013-05-02
Published