CVE-2013-4558Improper Input Validation in Apache Subversion

Severity
3.5LOWNVD
EPSS
1.8%
top 17.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 7
Latest updateMay 17

Description

The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request, as demonstrated using a trailing /.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 6.8 | Impact: 2.9

Affected Packages2 packages

Debianapache/subversion< 1.7.14-1+3
NVDapache/subversion7 versions+6

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6c6v-jhrm-ff4w: The get_parent_resource function in repos2022-05-17
CVEList
CVE-2013-4558: The get_parent_resource function in repos2013-12-07
OSV
CVE-2013-4558: The get_parent_resource function in repos2013-12-07

📋Vendor Advisories

4
Red Hat
subversion: mod_dav_svn assertion when handling certain requests with autoversioning enabled2013-11-25
Debian
CVE-2013-4558: subversion - The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server m...2013
Apache
Apache subversion: CVE-2013-4558
Apache
Apache httpd: CVE-2012-4558

💬Community

2
Bugzilla
CVE-2013-4505 CVE-2013-4558 subversion: various flaws [fedora-all]2013-11-25
Bugzilla
CVE-2013-4558 subversion: mod_dav_svn assertion when handling certain requests with autoversioning enabled2013-11-22
CVE-2013-4558 — Improper Input Validation in Apache | cvebase