CVE-2013-2112
published 2013-07-31CVE-2013-2112: The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection.
PriorityP336high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.89%
89.1th percentile
The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | <= 1.6.21 | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_apache7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2013-06-27·CVSS 2.1
CVE-2013-1845 [LOW] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in Subversion.
Alexander Klink discovered that the Subversion mod_dav_svn module for
Apache did not properly handle a large number of properties. A remote
authenticated attacker could use this flaw to cause memory consumption,
leading to a denial of service. (CVE-2013-1845)
Ben Reser discovered that the Subversion mod_dav_svn module for
Apache did not properly handle certain LOCKs. A remote authenticated
attacker could use this flaw to cause Subversion to crash, leading to a
denial of service. (CVE-2013-1846)
Philip Martin and Ben Reser discovered that the Subversion mod_dav_svn
module for Apache did not properly handle certain LOCKs. A remote
attacker could use this flaw to cause Subversion to crash, leading
Red Hat
subversion: Remote DoS due improper handling of early-closing TCP connections
vendor_redhat·2013-05-31·CVSS 7.8
CVE-2013-2112 [HIGH] subversion: Remote DoS due improper handling of early-closing TCP connections
subversion: Remote DoS due improper handling of early-closing TCP connections
The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection.
Statement: This issue affects the version of subversion as shipped with Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.
Debian
CVE-2013-2112: subversion - The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows r...
vendor_debian·2013·CVSS 7.8
CVE-2013-2112 [HIGH] CVE-2013-2112: subversion - The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows r...
The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection.
Scope: local
bookworm: resolved (fixed in 1.7.9-1+nmu2)
bullseye: resolved (fixed in 1.7.9-1+nmu2)
forky: resolved (fixed in 1.7.9-1+nmu2)
sid: resolved (fixed in 1.7.9-1+nmu2)
trixie: resolved (fixed in 1.7.9-1+nmu2)
Apache
Apache subversion: CVE-2013-2112
vendor_apache·CVSS 7.8
CVE-2013-2112 [HIGH] Apache subversion: CVE-2013-2112
Apache subversion: CVE-2013-2112
-advisory.txt 1.0.0-1.6.21 and 1.7.0-1.7.9 svnserve remotely triggerable DoS
GHSA
GHSA-44m8-rxc2-jwp2: The svnserve server in Subversion before 1
ghsa_unreviewed·2022-05-14
CVE-2013-2112 [HIGH] GHSA-44m8-rxc2-jwp2: The svnserve server in Subversion before 1
The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection.
OSV
CVE-2013-2112: The svnserve server in Subversion before 1
osv·2013-07-31·CVSS 7.8
CVE-2013-2112 [HIGH] CVE-2013-2112: The svnserve server in Subversion before 1
The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection.
Suricata
ET SNMP missing community string attempt 2
suricata·2013-01-09
CVE-1999-0517 ET SNMP missing community string attempt 2
ET SNMP missing community string attempt 2
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET 161 (msg:"ET SNMP missing community string attempt 2"; content:"|30|"; depth:1; byte_test:1,&,0x80,0,relative,big; byte_jump:1,0,relative; content:"|02|"; distance:-129; within:1; byte_test:1,&,0x80,0,relative,big; byte_jump:1,0,relative; content:"|04 00|"; distance:-129; within:2; reference:bugtraq,2112; reference:cve,1999-0517; classtype:misc-attack; sid:2016179; rev:2; metadata:created_at 2013_01_09, cve CVE_1999_0517, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)
Suricata
ET SNMP missing community string attempt 1
suricata·2013-01-09
CVE-1999-0517 ET SNMP missing community string attempt 1
ET SNMP missing community string attempt 1
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET 161 (msg:"ET SNMP missing community string attempt 1"; content:"|30|"; depth:1; byte_test:1,!&,0x80,0,relative,big; content:"|02|"; distance:1; within:1; byte_test:1,!&,0x80,0,relative,big; byte_jump:1,0,relative; content:"|04 00|"; within:2; reference:bugtraq,2112; reference:cve,1999-0517; classtype:misc-attack; sid:2016178; rev:2; metadata:created_at 2013_01_09, cve CVE_1999_0517, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)
Suricata
ET SNMP missing community string attempt 4
suricata·2013-01-09
CVE-1999-0517 ET SNMP missing community string attempt 4
ET SNMP missing community string attempt 4
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET 161 (msg:"ET SNMP missing community string attempt 4"; content:"|30|"; depth:1; byte_test:1,!&,0x80,0,relative,big; content:"|02|"; distance:1; within:1; byte_test:1,&,0x80,0,relative,big; byte_jump:1,0,relative; content:"|04 00|"; distance:-129; within:2; reference:bugtraq,2112; reference:cve,1999-0517; classtype:misc-attack; sid:2016181; rev:2; metadata:created_at 2013_01_09, cve CVE_1999_0517, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)
No public exploits indexed.
Bugzilla
CVE-2013-2112 subversion: Remote DoS due improper handling of early-closing TCP connections
bugzilla·2013-06-03·CVSS 7.8
CVE-2013-2112 [HIGH] CVE-2013-2112 subversion: Remote DoS due improper handling of early-closing TCP connections
CVE-2013-2112 subversion: Remote DoS due improper handling of early-closing TCP connections
A denial of service flaw was found in the way svnserve tool of Subversion, a concurrent version control system, managed remote client TCP connections that got closed early in the connection process (previously aborted connections were treated as critical errors, resulting into svnserve termination). A remote attacker could use this flaw to cause denial of service (svnserve daemon exit, leading to disruption of SVN service to other users).
References:
[1] http://subversion.apache.org/security/CVE-2013-2112-advisory.txt
Annoucements:
[2] http://mail-archives.apache.org/mod_mbox/subversion-dev/201305.mbox/%3CCADkdwvTxsMFeHgc8bK2V-2PrSrKoBffTi8+xbHA5tocrrewWew@mail.gmail.com%3E
(1.6.23)
[3] http://ma
Bugzilla
CVE-2013-2112 subversion: Remote DoS due improper handling of early-closing TCP connections [fedora-all]
bugzilla·2013-06-03·CVSS 7.8
CVE-2013-2112 [HIGH] CVE-2013-2112 subversion: Remote DoS due improper handling of early-closing TCP connections [fedora-all]
CVE-2013-2112 subversion: Remote DoS due improper handling of early-closing TCP connections [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
http://lists.opensuse.org/opensuse-updates/2013-07/msg00015.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvRK51pQsybfvsAzjxQJrmVpL0fEa1K4WGkUP9Tzz6KFDw%40mail.gmail.com%3Ehttp://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvTxsMFeHgc8bK2V-2PrSrKoBffTi8%2BxbHA5tocrrewWew%40mail.gmail.com%3Ehttp://rhn.redhat.com/errata/RHSA-2014-0255.htmlhttp://www.debian.org/security/2013/dsa-2703http://www.ubuntu.com/usn/USN-1893-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19057https://subversion.apache.org/security/CVE-2013-2112-advisory.txthttp://lists.opensuse.org/opensuse-updates/2013-07/msg00015.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvRK51pQsybfvsAzjxQJrmVpL0fEa1K4WGkUP9Tzz6KFDw%40mail.gmail.com%3Ehttp://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvTxsMFeHgc8bK2V-2PrSrKoBffTi8%2BxbHA5tocrrewWew%40mail.gmail.com%3Ehttp://rhn.redhat.com/errata/RHSA-2014-0255.htmlhttp://www.debian.org/security/2013/dsa-2703http://www.ubuntu.com/usn/USN-1893-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19057https://subversion.apache.org/security/CVE-2013-2112-advisory.txt
2013-07-31
Published