CVE-2014-8108
published 2014-12-18CVE-2014-8108: The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of…
PriorityP429medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
9.69%
95.0th percentile
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request for a URI that triggers a lookup for a virtual transaction name that does not exist.
Affected
104 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_apache5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2015-08-20·CVSS 5.0
CVE-2014-3580 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in Subversion.
It was discovered that the Subversion mod_dav_svn module incorrectly
handled REPORT requests for a resource that does not exist. A remote
attacker could use this issue to cause the server to crash, resulting in a
denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2014-3580)
It was discovered that the Subversion mod_dav_svn module incorrectly
handled requests requiring a lookup for a virtual transaction name that
does not exist. A remote attacker could use this issue to cause the server
to crash, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS. (CVE-2014-8108)
Evgeny Kotkov discovered that the Subversion mod_dav_svn module incorrec
Red Hat
subversion: NULL pointer dereference flaw in mod_dav_svn when handling URIs for virtual transaction names
vendor_redhat·2014-12-15·CVSS 5.0
CVE-2014-8108 [MEDIUM] CWE-476 subversion: NULL pointer dereference flaw in mod_dav_svn when handling URIs for virtual transaction names
subversion: NULL pointer dereference flaw in mod_dav_svn when handling URIs for virtual transaction names
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request for a URI that triggers a lookup for a virtual transaction name that does not exist.
A NULL pointer dereference flaw was found in the way the mod_dav_svn module handled certain requests for URIs that trigger a lookup of a virtual transaction name. A remote, unauthenticated attacker could send a request for a virtual transaction name that does not exist, causing mod_dav_svn to crash.
Statement: This issue did not affect the versions of subversion as shipped with Red Hat Enter
Debian
CVE-2014-8108: subversion - The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7...
vendor_debian·2014·CVSS 5.0
CVE-2014-8108 [MEDIUM] CVE-2014-8108: subversion - The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7...
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request for a URI that triggers a lookup for a virtual transaction name that does not exist.
Scope: local
bookworm: resolved (fixed in 1.8.10-5)
bullseye: resolved (fixed in 1.8.10-5)
forky: resolved (fixed in 1.8.10-5)
sid: resolved (fixed in 1.8.10-5)
trixie: resolved (fixed in 1.8.10-5)
Apple
CVE-2014-8108: Xcode 6.2
vendor_apple·CVSS 5.0
CVE-2014-8108 [MEDIUM] CVE-2014-8108: Xcode 6.2
Apple Security Update: About the security content of Xcode 6.2
Product: Xcode
Version: 6.2
CVE: CVE-2014-8108
Component: CVE-2014-8108
Apache
Apache subversion: CVE-2014-8108
vendor_apache·CVSS 5.0
CVE-2014-8108 [MEDIUM] Apache subversion: CVE-2014-8108
Apache subversion: CVE-2014-8108
-advisory.txt 1.7.0-1.7.18 and 1.8.0-1.8.10 mod_dav_svn DoS vulnerability with invalid virtual transaction names
GHSA
GHSA-vw28-xrgp-7gqj: The mod_dav_svn Apache HTTPD server module in Apache Subversion 1
ghsa_unreviewed·2022-05-17
CVE-2014-8108 [MEDIUM] GHSA-vw28-xrgp-7gqj: The mod_dav_svn Apache HTTPD server module in Apache Subversion 1
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request for a URI that triggers a lookup for a virtual transaction name that does not exist.
OSV
subversion vulnerabilities
osv·2015-08-20·CVSS 5.0
CVE-2014-3580 [MEDIUM] subversion vulnerabilities
subversion vulnerabilities
It was discovered that the Subversion mod_dav_svn module incorrectly
handled REPORT requests for a resource that does not exist. A remote
attacker could use this issue to cause the server to crash, resulting in a
denial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu
14.04 LTS. (CVE-2014-3580)
It was discovered that the Subversion mod_dav_svn module incorrectly
handled requests requiring a lookup for a virtual transaction name that
does not exist. A remote attacker could use this issue to cause the server
to crash, resulting in a denial of service. This issue only affected Ubuntu
14.04 LTS. (CVE-2014-8108)
Evgeny Kotkov discovered that the Subversion mod_dav_svn module incorrectly
handled large numbers of REPORT requests. A remote attacker cou
OSV
CVE-2014-8108: The mod_dav_svn Apache HTTPD server module in Apache Subversion 1
osv·2014-12-18·CVSS 5.0
CVE-2014-8108 [MEDIUM] CVE-2014-8108: The mod_dav_svn Apache HTTPD server module in Apache Subversion 1
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request for a URI that triggers a lookup for a virtual transaction name that does not exist.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8108 CVE-2014-3580 subversion: various flaws [fedora-all]
bugzilla·2014-12-16·CVSS 5.0
CVE-2014-8108 [MEDIUM] CVE-2014-8108 CVE-2014-3580 subversion: various flaws [fedora-all]
CVE-2014-8108 CVE-2014-3580 subversion: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
Bugzilla
CVE-2014-8108 subversion: NULL pointer dereference flaw in mod_dav_svn when handling URIs for virtual transaction names
bugzilla·2014-12-15·CVSS 5.0
CVE-2014-8108 [MEDIUM] CVE-2014-8108 subversion: NULL pointer dereference flaw in mod_dav_svn when handling URIs for virtual transaction names
CVE-2014-8108 subversion: NULL pointer dereference flaw in mod_dav_svn when handling URIs for virtual transaction names
A NULL pointer dereference flaw was found in the way mod_dav_svn handled URIs for virtual transaction names. A remote, unauthenticated attacker could send a request for a virtual transaction name that does not exist, causing mod_dav_svn to crash.
Versions 1.7.0 up to and including 1.7.18, and 1.8.0 up to and including 1.8.10, are affected.
This issue will be fixed in versions 1.7.19 and 1.8.11.
Acknowledgements:
Red Hat would like to thank the Subversion project for reporting this issue. Upstream acknowledges Evgeny Kotkov of VisualSVN as the original reporter.
Discussion:
Created attachment 968772
1.7.18 patch from upstream
---
Created attachment 968773
1.8.10 p
http://lists.apple.com/archives/security-announce/2015/Mar/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0166.htmlhttp://secunia.com/advisories/61131http://subversion.apache.org/security/CVE-2014-8108-advisory.txthttp://www.securityfocus.com/bid/71725http://www.ubuntu.com/usn/USN-2721-1https://support.apple.com/HT204427http://lists.apple.com/archives/security-announce/2015/Mar/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0166.htmlhttp://secunia.com/advisories/61131http://subversion.apache.org/security/CVE-2014-8108-advisory.txthttp://www.securityfocus.com/bid/71725http://www.ubuntu.com/usn/USN-2721-1https://support.apple.com/HT204427
2014-12-18
Published