CVE-2014-0032
published 2014-02-14CVE-2014-0032: The get_resource function in repos.c in the mod_dav_svn module in Apache Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is enabled…
PriorityP426medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
11.05%
95.4th percentile
The get_resource function in repos.c in the mod_dav_svn module in Apache Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is enabled, allows remote attackers to cause a denial of service (crash) via vectors related to the server root and request methods other than GET, as demonstrated by the "svn ls http://svn.example.com" command.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | <= 1.7.14 | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.8.8-1 | 1.8.8-1 |
| apache | subversion | >= 0 < 1.8.8-1 | 1.8.8-1 |
| apache | subversion | >= 0 < 1.8.8-1 | 1.8.8-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_apache4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2014-08-14·CVSS 4.3
CVE-2014-0032 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in Subversion.
Lieven Govaerts discovered that the Subversion mod_dav_svn module
incorrectly handled certain request methods when SVNListParentPath was
enabled. A remote attacker could use this issue to cause the server to
crash, resulting in a denial of service. This issue only affected Ubuntu
12.04 LTS. (CVE-2014-0032)
Ben Reser discovered that Subversion did not correctly validate SSL
certificates containing wildcards. A remote attacker could exploit this to
perform a machine-in-the-middle attack to view sensitive information or alter
encrypted communications. (CVE-2014-3522)
Bert Huijben discovered that Subversion did not properly handle cached
credentials. A malicious server could possibly use this issue
Red Hat
subversion: mod_dav_svn crash when handling certain requests with SVNListParentPath on
vendor_redhat·2014-01-10·CVSS 4.3
CVE-2014-0032 [MEDIUM] subversion: mod_dav_svn crash when handling certain requests with SVNListParentPath on
subversion: mod_dav_svn crash when handling certain requests with SVNListParentPath on
The get_resource function in repos.c in the mod_dav_svn module in Apache Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is enabled, allows remote attackers to cause a denial of service (crash) via vectors related to the server root and request methods other than GET, as demonstrated by the "svn ls http://svn.example.com" command.
Package: subversion (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2014-0032: subversion - The get_resource function in repos.c in the mod_dav_svn module in Apache Subvers...
vendor_debian·2014·CVSS 4.3
CVE-2014-0032 [MEDIUM] CVE-2014-0032: subversion - The get_resource function in repos.c in the mod_dav_svn module in Apache Subvers...
The get_resource function in repos.c in the mod_dav_svn module in Apache Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is enabled, allows remote attackers to cause a denial of service (crash) via vectors related to the server root and request methods other than GET, as demonstrated by the "svn ls http://svn.example.com" command.
Scope: local
bookworm: resolved (fixed in 1.8.8-1)
bullseye: resolved (fixed in 1.8.8-1)
forky: resolved (fixed in 1.8.8-1)
sid: resolved (fixed in 1.8.8-1)
trixie: resolved (fixed in 1.8.8-1)
Apache
Apache subversion: CVE-2014-0032
vendor_apache·CVSS 4.3
CVE-2014-0032 [MEDIUM] Apache subversion: CVE-2014-0032
Apache subversion: CVE-2014-0032
-advisory.txt 1.3.0-1.7.14 and 1.8.0-1.8.5 mod_dav_svn DoS vulnerability with SVNListParentPath
GHSA
GHSA-5jv6-mmqm-cjvm: The get_resource function in repos
ghsa_unreviewed·2022-05-17
CVE-2014-0032 [MEDIUM] CWE-20 GHSA-5jv6-mmqm-cjvm: The get_resource function in repos
The get_resource function in repos.c in the mod_dav_svn module in Apache Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is enabled, allows remote attackers to cause a denial of service (crash) via vectors related to the server root and request methods other than GET, as demonstrated by the "svn ls http://svn.example.com" command.
OSV
subversion vulnerabilities
osv·2014-08-14·CVSS 4.3
CVE-2014-0032 [MEDIUM] subversion vulnerabilities
subversion vulnerabilities
Lieven Govaerts discovered that the Subversion mod_dav_svn module
incorrectly handled certain request methods when SVNListParentPath was
enabled. A remote attacker could use this issue to cause the server to
crash, resulting in a denial of service. This issue only affected Ubuntu
12.04 LTS. (CVE-2014-0032)
Ben Reser discovered that Subversion did not correctly validate SSL
certificates containing wildcards. A remote attacker could exploit this to
perform a machine-in-the-middle attack to view sensitive information or alter
encrypted communications. (CVE-2014-3522)
Bert Huijben discovered that Subversion did not properly handle cached
credentials. A malicious server could possibly use this issue to obtain
credentials cached for a different server. (CVE-2014-352
OSV
CVE-2014-0032: The get_resource function in repos
osv·2014-02-14·CVSS 4.3
CVE-2014-0032 [MEDIUM] CVE-2014-0032: The get_resource function in repos
The get_resource function in repos.c in the mod_dav_svn module in Apache Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is enabled, allows remote attackers to cause a denial of service (crash) via vectors related to the server root and request methods other than GET, as demonstrated by the "svn ls http://svn.example.com" command.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0032 subversion: mod_dav_svn crash when handling certain requests with SVNListParentPath on [fedora-all]
bugzilla·2014-02-10·CVSS 4.3
CVE-2014-0032 [MEDIUM] CVE-2014-0032 subversion: mod_dav_svn crash when handling certain requests with SVNListParentPath on [fedora-all]
CVE-2014-0032 subversion: mod_dav_svn crash when handling certain requests with SVNListParentPath on [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when ava
Bugzilla
CVE-2014-0032 subversion: mod_dav_svn crash when handling certain requests with SVNListParentPath on
bugzilla·2014-02-06·CVSS 4.3
CVE-2014-0032 [MEDIUM] CVE-2014-0032 subversion: mod_dav_svn crash when handling certain requests with SVNListParentPath on
CVE-2014-0032 subversion: mod_dav_svn crash when handling certain requests with SVNListParentPath on
A mod_dav_svn crash was reported when SVNListParentPath is on:
http://mail-archives.apache.org/mod_mbox/subversion-dev/201401.mbox/%3CCANvU9scLHr2yOLABW8q6_wNzhEf7pWM=NiavGcobqvUuyhKyAA@mail.gmail.com%3E
Certain requests could cause mod_dav_svn to crash.
This has been corrected in version 1.7.15:
https://svn.apache.org/repos/asf/subversion/branches/1.7.x/CHANGES
Upstream fix for CVE-2014-0032:
http://svn.apache.org/viewvc?view=revision&revision=r1557320
Discussion:
This issue affects the version of subversion as shipped with Red Hat Enterprise Linux 5 and 6.
---
Created subversion tracking bugs for this issue:
Affects: fedora-all [bug 1063204]
---
External References:
http://
http://lists.opensuse.org/opensuse-updates/2014-02/msg00086.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00011.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-dev/201401.mbox/%3C52D328AB.8090502%40reser.org%3Ehttp://mail-archives.apache.org/mod_mbox/subversion-dev/201401.mbox/%3C871u0gqb0d.fsf%40ntlworld.com%3Ehttp://mail-archives.apache.org/mod_mbox/subversion-dev/201401.mbox/%3CCANvU9scLHr2yOLABW8q6_wNzhEf7pWM=NiavGcobqvUuyhKyAA%40mail.gmail.com%3Ehttp://rhn.redhat.com/errata/RHSA-2014-0255.htmlhttp://secunia.com/advisories/56822http://secunia.com/advisories/60722http://secunia.com/advisories/61321http://support.apple.com/kb/HT6444http://svn.apache.org/repos/asf/subversion/tags/1.7.15/CHANGEShttp://svn.apache.org/repos/asf/subversion/tags/1.8.6/CHANGEShttp://svn.apache.org/viewvc?view=revision&revision=1557320http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.osvdb.org/102927http://www.securityfocus.com/bid/65434http://www.ubuntu.com/usn/USN-2316-1https://exchange.xforce.ibmcloud.com/vulnerabilities/90986https://security.gentoo.org/glsa/201610-05http://lists.opensuse.org/opensuse-updates/2014-02/msg00086.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00011.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-dev/201401.mbox/%3C52D328AB.8090502%40reser.org%3Ehttp://mail-archives.apache.org/mod_mbox/subversion-dev/201401.mbox/%3C871u0gqb0d.fsf%40ntlworld.com%3Ehttp://mail-archives.apache.org/mod_mbox/subversion-dev/201401.mbox/%3CCANvU9scLHr2yOLABW8q6_wNzhEf7pWM=NiavGcobqvUuyhKyAA%40mail.gmail.com%3Ehttp://rhn.redhat.com/errata/RHSA-2014-0255.htmlhttp://secunia.com/advisories/56822http://secunia.com/advisories/60722http://secunia.com/advisories/61321http://support.apple.com/kb/HT6444http://svn.apache.org/repos/asf/subversion/tags/1.7.15/CHANGEShttp://svn.apache.org/repos/asf/subversion/tags/1.8.6/CHANGEShttp://svn.apache.org/viewvc?view=revision&revision=1557320http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.osvdb.org/102927http://www.securityfocus.com/bid/65434http://www.ubuntu.com/usn/USN-2316-1https://exchange.xforce.ibmcloud.com/vulnerabilities/90986https://security.gentoo.org/glsa/201610-05
2014-02-14
Published