CVE-2013-1968
published 2013-07-31CVE-2013-1968: Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline…
PriorityP421medium5.5CVSS 2.0
AVNACLAuSCNIPAP
EPSS
2.81%
85.1th percentile
Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | <= 1.6.21 | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
osv5.5MEDIUM
vendor_apache5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rx9x-73jj-929p: Subversion before 1
ghsa_unreviewed·2022-05-14
CVE-2013-1968 [MEDIUM] GHSA-rx9x-73jj-929p: Subversion before 1
Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name.
OSV
CVE-2013-1968: Subversion before 1
osv·2013-07-31·CVSS 5.5
CVE-2013-1968 [MEDIUM] CVE-2013-1968: Subversion before 1
Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2013-06-27·CVSS 2.1
CVE-2013-1845 [LOW] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in Subversion.
Alexander Klink discovered that the Subversion mod_dav_svn module for
Apache did not properly handle a large number of properties. A remote
authenticated attacker could use this flaw to cause memory consumption,
leading to a denial of service. (CVE-2013-1845)
Ben Reser discovered that the Subversion mod_dav_svn module for
Apache did not properly handle certain LOCKs. A remote authenticated
attacker could use this flaw to cause Subversion to crash, leading to a
denial of service. (CVE-2013-1846)
Philip Martin and Ben Reser discovered that the Subversion mod_dav_svn
module for Apache did not properly handle certain LOCKs. A remote
attacker could use this flaw to cause Subversion to crash, leading
Red Hat
format): Filenames with newline character can lead to revision corruption
vendor_redhat·2013-05-31·CVSS 5.5
CVE-2013-1968 [MEDIUM] CWE-138 format): Filenames with newline character can lead to revision corruption
format): Filenames with newline character can lead to revision corruption
Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name.
Statement: This issue affects the version of subversion as shipped with Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.
Debian
CVE-2013-1968: subversion - Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated use...
vendor_debian·2013·CVSS 5.5
CVE-2013-1968 [MEDIUM] CVE-2013-1968: subversion - Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated use...
Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name.
Scope: local
bookworm: resolved (fixed in 1.7.9-1+nmu2)
bullseye: resolved (fixed in 1.7.9-1+nmu2)
forky: resolved (fixed in 1.7.9-1+nmu2)
sid: resolved (fixed in 1.7.9-1+nmu2)
trixie: resolved (fixed in 1.7.9-1+nmu2)
Apache
Apache subversion: CVE-2013-1968
vendor_apache·CVSS 5.5
CVE-2013-1968 [MEDIUM] Apache subversion: CVE-2013-1968
Apache subversion: CVE-2013-1968
-advisory.txt 1.1.0-1.6.23 and 1.7.0-1.7.9 fsfs repositories can be corrupted by newline characters in filenames
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1968 subversion (FSFS format): Filenames with newline character can lead to revision corruption
bugzilla·2013-06-03·CVSS 5.5
CVE-2013-1968 [MEDIUM] CVE-2013-1968 subversion (FSFS format): Filenames with newline character can lead to revision corruption
CVE-2013-1968 subversion (FSFS format): Filenames with newline character can lead to revision corruption
A security flaw was found in the way FSFS repository format functionality of Subversion, a concurrent version control system, processed filenames containing newline (ASCII 0x0a) character sequence. Remote attacker (via malicious client) could commit a revision for the FSFS repository, containing specially-crafted content that in subsequent requests could lead to disruption of the service of that repository for other users.
References:
[1] http://subversion.apache.org/security/CVE-2013-1968-advisory.txt
Announcements:
[2] http://mail-archives.apache.org/mod_mbox/subversion-dev/201305.mbox/%3CCADkdwvTxsMFeHgc8bK2V-2PrSrKoBffTi8+xbHA5tocrrewWew@mail.gmail.com%3E
(1.6.23)
[3] http://mail
Bugzilla
CVE-2013-1968 subversion (FSFS format): Filenames with newline character can lead to revision corruption [fedora-all]
bugzilla·2013-06-03·CVSS 5.5
CVE-2013-1968 [MEDIUM] CVE-2013-1968 subversion (FSFS format): Filenames with newline character can lead to revision corruption [fedora-all]
CVE-2013-1968 subversion (FSFS format): Filenames with newline character can lead to revision corruption [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when
http://lists.opensuse.org/opensuse-updates/2013-07/msg00015.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvRK51pQsybfvsAzjxQJrmVpL0fEa1K4WGkUP9Tzz6KFDw%40mail.gmail.com%3Ehttp://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvTxsMFeHgc8bK2V-2PrSrKoBffTi8%2BxbHA5tocrrewWew%40mail.gmail.com%3Ehttp://rhn.redhat.com/errata/RHSA-2014-0255.htmlhttp://www.debian.org/security/2013/dsa-2703http://www.ubuntu.com/usn/USN-1893-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18986https://subversion.apache.org/security/CVE-2013-1968-advisory.txthttp://lists.opensuse.org/opensuse-updates/2013-07/msg00015.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvRK51pQsybfvsAzjxQJrmVpL0fEa1K4WGkUP9Tzz6KFDw%40mail.gmail.com%3Ehttp://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvTxsMFeHgc8bK2V-2PrSrKoBffTi8%2BxbHA5tocrrewWew%40mail.gmail.com%3Ehttp://rhn.redhat.com/errata/RHSA-2014-0255.htmlhttp://www.debian.org/security/2013/dsa-2703http://www.ubuntu.com/usn/USN-1893-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18986https://subversion.apache.org/security/CVE-2013-1968-advisory.txt
2013-07-31
Published