CVE-2013-4558
published 2013-12-07CVE-2013-4558: The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built…
PriorityP420low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
5.88%
92.4th percentile
The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request, as demonstrated using a trailing /.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | httpd | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.7.14-1 | 1.7.14-1 |
| apache | subversion | >= 0 < 1.7.14-1 | 1.7.14-1 |
| apache | subversion | >= 0 < 1.7.14-1 | 1.7.14-1 |
| apache | subversion | >= 0 < 1.7.14-1 | 1.7.14-1 |
| debian | subversion | < subversion 1.7.14-1 (bookworm) | subversion 1.7.14-1 (bookworm) |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv3.5LOW
vendor_apache4.3
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
subversion: mod_dav_svn assertion when handling certain requests with autoversioning enabled
vendor_redhat·2013-11-25·CVSS 3.5
CVE-2013-4558 [LOW] subversion: mod_dav_svn assertion when handling certain requests with autoversioning enabled
subversion: mod_dav_svn assertion when handling certain requests with autoversioning enabled
The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request, as demonstrated using a trailing /.
Statement: Not vulnerable. This issue did not affect the versions of Subversion in Red Hat Enterprise Linux 5 and 6.
Package: subversion (Red Hat Enterprise Linux 5) - Not affected
Package: subversion (Red Hat Enterprise Linux 6) - Not affected
Package: subversion (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-4558: subversion - The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server m...
vendor_debian·2013·CVSS 3.5
CVE-2013-4558 [LOW] CVE-2013-4558: subversion - The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server m...
The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request, as demonstrated using a trailing /.
Scope: local
bookworm: resolved (fixed in 1.7.14-1)
bullseye: resolved (fixed in 1.7.14-1)
forky: resolved (fixed in 1.7.14-1)
sid: resolved (fixed in 1.7.14-1)
trixie: resolved (fixed in 1.7.14-1)
Apache
Apache subversion: CVE-2013-4558
vendor_apache·CVSS 3.5
CVE-2013-4558 [LOW] Apache subversion: CVE-2013-4558
Apache subversion: CVE-2013-4558
-advisory.txt 1.7.11-1.7.13 and 1.8.1-1.8.4 mod_dav_svn assertion triggered by non-canonical URLs in autoversioning commits
Apache
Apache httpd: CVE-2012-4558
vendor_apache·CVSS 4.3
CVE-2012-4558 Apache httpd: CVE-2012-4558
Apache httpd: CVE-2012-4558
A XSS flaw affected the mod_proxy_balancer manager interface. Acknowledgements: This issue was reported by Niels Heinen of Google Reported to security team 2012-10-07 Issue public 2013-02-18 Update 2.4.4 released 2013-02-25 Update 2.2.24 released 2013-02-25 Affects 2.4.3, 2.4.2, 2.4.1, 2.2.23, 2.2.22, 2.2.21, 2.2.20, 2.2.19, 2.2.18, 2.2.17, 2.2.16, 2.2.15, 2.2.14, 2.2.13, 2.2.12, 2.2.11, 2.2.10, 2.2.9, 2.2.8, 2.2.6, 2.2.5, 2.2.4, 2.2.3, 2.2.2, 2.2.0
Severity: moderate
GHSA
GHSA-6c6v-jhrm-ff4w: The get_parent_resource function in repos
ghsa_unreviewed·2022-05-17
CVE-2013-4558 [LOW] CWE-20 GHSA-6c6v-jhrm-ff4w: The get_parent_resource function in repos
The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request, as demonstrated using a trailing /.
OSV
CVE-2013-4558: The get_parent_resource function in repos
osv·2013-12-07·CVSS 3.5
CVE-2013-4558 [LOW] CVE-2013-4558: The get_parent_resource function in repos
The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request, as demonstrated using a trailing /.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4505 CVE-2013-4558 subversion: various flaws [fedora-all]
bugzilla·2013-11-25·CVSS 2.6
CVE-2013-4505 [LOW] CVE-2013-4505 CVE-2013-4558 subversion: various flaws [fedora-all]
CVE-2013-4505 CVE-2013-4558 subversion: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multip
Bugzilla
CVE-2013-4558 subversion: mod_dav_svn assertion when handling certain requests with autoversioning enabled
bugzilla·2013-11-22·CVSS 3.5
CVE-2013-4558 [LOW] CVE-2013-4558 subversion: mod_dav_svn assertion when handling certain requests with autoversioning enabled
CVE-2013-4558 subversion: mod_dav_svn assertion when handling certain requests with autoversioning enabled
A flaw was found in the way mod_dav_svn handled certain requests when SVNAutoversioning (in "/etc/httpd/conf.d/subversion.conf", for example) was enabled. If an attacker with commit access to a repository sent a request containing a crafted URL, it would cause the httpd process serving the request to crash.
This issue affected Subversion versions 1.7.11 to 1.7.13, and 1.8.1 to 1.8.4. It has been corrected in versions 1.7.14 and 1.8.5.
This issue does not affect the versions of Subversion in Red Hat Enterprise Linux 5 and 6.
Acknowledgements:
Red Hat would like to thank the Apache Subversion project for reporting this issue. Upstream acknowledges Philip Martin as the original repo
http://lists.opensuse.org/opensuse-updates/2013-12/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00048.htmlhttp://osvdb.org/100363http://subversion.apache.org/security/CVE-2013-4558-advisory.txthttps://bugzilla.redhat.com/show_bug.cgi?id=1033431https://github.com/apache/subversion/commit/2c77c43e4255555f3b79f761f0d141393a3856cchttps://github.com/apache/subversion/commit/647e3f8365a74831bb915f63793b63e31fae062dhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00029.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00048.htmlhttp://osvdb.org/100363http://subversion.apache.org/security/CVE-2013-4558-advisory.txthttps://bugzilla.redhat.com/show_bug.cgi?id=1033431https://github.com/apache/subversion/commit/2c77c43e4255555f3b79f761f0d141393a3856cchttps://github.com/apache/subversion/commit/647e3f8365a74831bb915f63793b63e31fae062d
2013-12-07
Published