CVE-2014-3580
published 2014-12-18CVE-2014-3580: The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service…
PriorityP428medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
10.67%
95.3th percentile
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.
Affected
111 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_apache5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2015-08-20·CVSS 5.0
CVE-2014-3580 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in Subversion.
It was discovered that the Subversion mod_dav_svn module incorrectly
handled REPORT requests for a resource that does not exist. A remote
attacker could use this issue to cause the server to crash, resulting in a
denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2014-3580)
It was discovered that the Subversion mod_dav_svn module incorrectly
handled requests requiring a lookup for a virtual transaction name that
does not exist. A remote attacker could use this issue to cause the server
to crash, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS. (CVE-2014-8108)
Evgeny Kotkov discovered that the Subversion mod_dav_svn module incorrec
Red Hat
subversion: NULL pointer dereference flaw in mod_dav_svn when handling REPORT requests
vendor_redhat·2014-12-15·CVSS 5.0
CVE-2014-3580 [MEDIUM] CWE-476 subversion: NULL pointer dereference flaw in mod_dav_svn when handling REPORT requests
subversion: NULL pointer dereference flaw in mod_dav_svn when handling REPORT requests
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.
A NULL pointer dereference flaw was found in the way the mod_dav_svn module handled REPORT requests. A remote, unauthenticated attacker could use a specially crafted REPORT request to crash mod_dav_svn.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional inf
Debian
CVE-2014-3580: subversion - The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.1...
vendor_debian·2014·CVSS 5.0
CVE-2014-3580 [MEDIUM] CVE-2014-3580: subversion - The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.1...
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.
Scope: local
bookworm: resolved (fixed in 1.8.10-5)
bullseye: resolved (fixed in 1.8.10-5)
forky: resolved (fixed in 1.8.10-5)
sid: resolved (fixed in 1.8.10-5)
trixie: resolved (fixed in 1.8.10-5)
Apache
Apache subversion: CVE-2014-3580
vendor_apache·CVSS 5.0
CVE-2014-3580 [MEDIUM] Apache subversion: CVE-2014-3580
Apache subversion: CVE-2014-3580
-advisory.txt 1.0.0-1.7.18 and 1.8.0-1.8.10 mod_dav_svn DoS vulnerability with invalid REPORT requests
Apple
CVE-2014-3580: Xcode 6.2
vendor_apple·CVSS 5.0
CVE-2014-3580 [MEDIUM] CVE-2014-3580: Xcode 6.2
Apple Security Update: About the security content of Xcode 6.2
Product: Xcode
Version: 6.2
CVE: CVE-2014-3580
Component: CVE-2014-3580
GHSA
GHSA-x4g6-pj88-5h4h: The mod_dav_svn Apache HTTPD server module in Apache Subversion 1
ghsa_unreviewed·2022-05-17
CVE-2014-3580 [MEDIUM] GHSA-x4g6-pj88-5h4h: The mod_dav_svn Apache HTTPD server module in Apache Subversion 1
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.
OSV
subversion vulnerabilities
osv·2015-08-20·CVSS 5.0
CVE-2014-3580 [MEDIUM] subversion vulnerabilities
subversion vulnerabilities
It was discovered that the Subversion mod_dav_svn module incorrectly
handled REPORT requests for a resource that does not exist. A remote
attacker could use this issue to cause the server to crash, resulting in a
denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2014-3580)
It was discovered that the Subversion mod_dav_svn module incorrectly
handled requests requiring a lookup for a virtual transaction name that
does not exist. A remote attacker could use this issue to cause the server
to crash, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS. (CVE-2014-8108)
Evgeny Kotkov discovered that the Subversion mod_dav_svn module incorrectly
handled large numbers of REPORT requests. A remote attacker cou
OSV
CVE-2014-3580: The mod_dav_svn Apache HTTPD server module in Apache Subversion 1
osv·2014-12-18·CVSS 5.0
CVE-2014-3580 [MEDIUM] CVE-2014-3580: The mod_dav_svn Apache HTTPD server module in Apache Subversion 1
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8108 CVE-2014-3580 subversion: various flaws [fedora-all]
bugzilla·2014-12-16·CVSS 5.0
CVE-2014-8108 [MEDIUM] CVE-2014-8108 CVE-2014-3580 subversion: various flaws [fedora-all]
CVE-2014-8108 CVE-2014-3580 subversion: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
Bugzilla
CVE-2014-3580 subversion: NULL pointer dereference flaw in mod_dav_svn when handling REPORT requests
bugzilla·2014-12-15·CVSS 5.0
CVE-2014-3580 [MEDIUM] CVE-2014-3580 subversion: NULL pointer dereference flaw in mod_dav_svn when handling REPORT requests
CVE-2014-3580 subversion: NULL pointer dereference flaw in mod_dav_svn when handling REPORT requests
A NULL pointer dereference flaw was found in the way mod_dav_svn handled REPORT requests. A remote, unauthenticated attacker could use a crafted REPORT request to crash mod_dav_svn.
Versions 1.0.0 up to and including 1.7.18, and 1.8.0 up to and including 1.8.10, are affected.
This issue will be fixed in versions 1.7.19 and 1.8.11.
Acknowledgements:
Red Hat would like to thank the Subversion project for reporting this issue. Upstream acknowledges Evgeny Kotkov of VisualSVN as the original reporter.
Discussion:
Created attachment 968769
1.7.18 patch from upstream
---
Created attachment 968770
1.8.10 patch from upstream
---
External References:
http://subversion.apache.org/security
http://lists.apple.com/archives/security-announce/2015/Mar/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0165.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0166.htmlhttp://secunia.com/advisories/61131http://subversion.apache.org/security/CVE-2014-3580-advisory.txthttp://www.debian.org/security/2014/dsa-3107http://www.securityfocus.com/bid/71726http://www.ubuntu.com/usn/USN-2721-1https://support.apple.com/HT204427http://lists.apple.com/archives/security-announce/2015/Mar/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0165.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0166.htmlhttp://secunia.com/advisories/61131http://subversion.apache.org/security/CVE-2014-3580-advisory.txthttp://www.debian.org/security/2014/dsa-3107http://www.securityfocus.com/bid/71726http://www.ubuntu.com/usn/USN-2721-1https://support.apple.com/HT204427
2014-12-18
Published