CVE-2013-4131
published 2013-07-31CVE-2013-4131: The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 and 1.8.x before 1.8.1 allows remote authenticated users to cause a denial of…
PriorityP419medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
4.38%
90.3th percentile
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 and 1.8.x before 1.8.1 allows remote authenticated users to cause a denial of service (assertion failure or out-of-bounds read) via a certain (1) COPY, (2) DELETE, or (3) MOVE request against a revision root.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.7.13-1 | 1.7.13-1 |
| apache | subversion | >= 0 < 1.7.13-1 | 1.7.13-1 |
| apache | subversion | >= 0 < 1.7.13-1 | 1.7.13-1 |
| apache | subversion | >= 0 < 1.7.13-1 | 1.7.13-1 |
| debian | subversion | < subversion 1.7.13-1 (bookworm) | subversion 1.7.13-1 (bookworm) |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM
vendor_apache4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-632g-wm7q-4fjw: The mod_dav_svn Apache HTTPD server module in Subversion 1
ghsa_unreviewed·2022-05-17
CVE-2013-4131 [MEDIUM] CWE-119 GHSA-632g-wm7q-4fjw: The mod_dav_svn Apache HTTPD server module in Subversion 1
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 and 1.8.x before 1.8.1 allows remote authenticated users to cause a denial of service (assertion failure or out-of-bounds read) via a certain (1) COPY, (2) DELETE, or (3) MOVE request against a revision root.
OSV
CVE-2013-4131: The mod_dav_svn Apache HTTPD server module in Subversion 1
osv·2013-07-31·CVSS 4.0
CVE-2013-4131 [MEDIUM] CVE-2013-4131: The mod_dav_svn Apache HTTPD server module in Subversion 1
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 and 1.8.x before 1.8.1 allows remote authenticated users to cause a denial of service (assertion failure or out-of-bounds read) via a certain (1) COPY, (2) DELETE, or (3) MOVE request against a revision root.
Red Hat
subversion: DoS (assertion failure, crash) in mod_dav_svn when handling certain MOVE, COPY, or DELETE HTTP requests
vendor_redhat·2013-07-24·CVSS 4.0
CVE-2013-4131 [MEDIUM] subversion: DoS (assertion failure, crash) in mod_dav_svn when handling certain MOVE, COPY, or DELETE HTTP requests
subversion: DoS (assertion failure, crash) in mod_dav_svn when handling certain MOVE, COPY, or DELETE HTTP requests
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 and 1.8.x before 1.8.1 allows remote authenticated users to cause a denial of service (assertion failure or out-of-bounds read) via a certain (1) COPY, (2) DELETE, or (3) MOVE request against a revision root.
Statement: Not vulnerable. This issue did not affect the versions of subversion, as shipped with Red Hat Enterprise Linux 5 and 6.
Package: subversion (Red Hat Enterprise Linux 5) - Not affected
Package: subversion (Red Hat Enterprise Linux 6) - Not affected
Package: subversion (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-4131: subversion - The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 an...
vendor_debian·2013·CVSS 4.0
CVE-2013-4131 [MEDIUM] CVE-2013-4131: subversion - The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 an...
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 and 1.8.x before 1.8.1 allows remote authenticated users to cause a denial of service (assertion failure or out-of-bounds read) via a certain (1) COPY, (2) DELETE, or (3) MOVE request against a revision root.
Scope: local
bookworm: resolved (fixed in 1.7.13-1)
bullseye: resolved (fixed in 1.7.13-1)
forky: resolved (fixed in 1.7.13-1)
sid: resolved (fixed in 1.7.13-1)
trixie: resolved (fixed in 1.7.13-1)
Apache
Apache subversion: CVE-2013-4131
vendor_apache·CVSS 4.0
CVE-2013-4131 [MEDIUM] Apache subversion: CVE-2013-4131
Apache subversion: CVE-2013-4131
-advisory.txt 1.6.0-1.7.10 and 1.8.0 mod_dav_svn assertion from requests against root path
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4131 subversion: DoS (assertion failure, crash) in mod_dav_svn when handling certain MOVE, COPY, or DELETE HTTP requests [fedora-all]
bugzilla·2013-07-24·CVSS 4.0
CVE-2013-4131 [MEDIUM] CVE-2013-4131 subversion: DoS (assertion failure, crash) in mod_dav_svn when handling certain MOVE, COPY, or DELETE HTTP requests [fedora-all]
CVE-2013-4131 subversion: DoS (assertion failure, crash) in mod_dav_svn when handling certain MOVE, COPY, or DELETE HTTP requests [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and t
Bugzilla
CVE-2013-4131 subversion: DoS (assertion failure, crash) in mod_dav_svn when handling certain MOVE, COPY, or DELETE HTTP requests
bugzilla·2013-07-19·CVSS 4.0
CVE-2013-4131 [MEDIUM] CVE-2013-4131 subversion: DoS (assertion failure, crash) in mod_dav_svn when handling certain MOVE, COPY, or DELETE HTTP requests
CVE-2013-4131 subversion: DoS (assertion failure, crash) in mod_dav_svn when handling certain MOVE, COPY, or DELETE HTTP requests
A denial of service flaw was found in the way mod_dav_svn module of Subversion (SVN), a concurrent version control system, used to process certain MOVE, COPY, or DELETE HTTP requests (requests that originated or targeted against a revision root). A remote attacker, with commit access / privileges could use this flaw to cause denial of service (depending on the Apache httpd web server configuration either child assertion failure or crash [prefork MPM configuration] or failure to handle other requests, originally scheduled to be handled within the same thread [threaded MPM configuration] due to a process termination) by issuing a specially-crafted SVN commit requ
http://lists.opensuse.org/opensuse-updates/2013-08/msg00000.htmlhttp://subversion.apache.org/security/CVE-2013-4131-advisory.txthttp://www.securityfocus.com/bid/61454https://bugzilla.redhat.com/show_bug.cgi?id=986194https://exchange.xforce.ibmcloud.com/vulnerabilities/85983https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18621http://lists.opensuse.org/opensuse-updates/2013-08/msg00000.htmlhttp://subversion.apache.org/security/CVE-2013-4131-advisory.txthttp://www.securityfocus.com/bid/61454https://bugzilla.redhat.com/show_bug.cgi?id=986194https://exchange.xforce.ibmcloud.com/vulnerabilities/85983https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18621
2013-07-31
Published