CVE-2018-11803
published 2019-02-05CVE-2018-11803: Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits…
PriorityP357high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
57.82%
99.0th percentile
Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.10.4-1 | 1.10.4-1 |
| apache | subversion | >= 0 < 1.10.4-1 | 1.10.4-1 |
| apache | subversion | >= 0 < 1.10.4-1 | 1.10.4-1 |
| apache | subversion | >= 0 < 1.10.4-1 | 1.10.4-1 |
| apache | subversion | 1.10.0 – 1.10.3 | — |
| apache_software_foundation | apache_subversion | — | — |
| canonical | ubuntu_linux | — | — |
| debian | subversion | < subversion 1.10.4-1 (bookworm) | subversion 1.10.4-1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered when a malicious SVN client omits the root path in a recursive directory listing operation against mod_dav_svn. Monitor for SVN REPORT requests (used for recursive directory listings) that lack a root path element, which will cause the HTTPD worker process to crash — detectable as an abnormal Apache worker process termination. ↗
- →Affected versions are mod_dav_svn as shipped with Subversion 1.10.0–1.10.3 and 1.11.0. Detection should focus on identifying these specific version strings in deployed Apache HTTPD modules. ↗
- →Subversion 1.10.0 introduced server-side support for recursive directory listing operations — this feature's introduction is the root cause. Environments running Subversion 1.10.0+ with mod_dav_svn exposed to untrusted clients are at risk. ↗
- ·The vulnerability only affects mod_dav_svn when it is actively loaded and used as an Apache HTTPD module. Subversion deployments not using mod_dav_svn (e.g., svnserve) are not affected. ↗
- ·Red Hat Enterprise Linux 5, 6, and 7 ship versions of Subversion that are not affected; only RHEL 8 (and Fedora) carry the vulnerable version range. ↗
- ·The advisory and fix are documented at the Apache Subversion security page; the advisory text (CVE-2018-11803-advisory.txt) and its PGP signature are available for verification. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerability
vendor_ubuntu·2019-01-24
CVE-2018-11803 Subversion vulnerability
Title: Subversion vulnerability
Summary: Subversion could be made to crash if it received a specially crafted input.
Ivan Zhakov discovered that Subversion incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
subversion: malicious SVN clients can crash mod_dav_svn
vendor_redhat·2019-01-18·CVSS 7.5
CVE-2018-11803 [HIGH] CWE-476 subversion: malicious SVN clients can crash mod_dav_svn
subversion: malicious SVN clients can crash mod_dav_svn
Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.
Statement: This issue did not affect the versions of subversion as shipped with Red Hat Enterprise Linux 5, 6, and 7.
This issue does not affect any Ansible Tower supported versions: 3.2, 3.3 or 3.4, as their system jobs don't use mod_dav_svn module.
Package: subversion (Red Hat Ansible Tower 3) - Not affected
Package: subversion (Red Hat Enterprise Linux 5) - Not affected
Package: subversion (Red Hat Enterprise Linux 6) - Not affected
Package: subversion (Red Hat Enterprise Linux 7) - Not affected
Package: subversi
Debian
CVE-2018-11803: subversion - Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10....
vendor_debian·2018·CVSS 7.5
CVE-2018-11803 [HIGH] CVE-2018-11803: subversion - Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10....
Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.
Scope: local
bookworm: resolved (fixed in 1.10.4-1)
bullseye: resolved (fixed in 1.10.4-1)
forky: resolved (fixed in 1.10.4-1)
sid: resolved (fixed in 1.10.4-1)
trixie: resolved (fixed in 1.10.4-1)
Apache
Apache subversion: CVE-2018-11803
vendor_apache·CVSS 7.5
CVE-2018-11803 [HIGH] Apache subversion: CVE-2018-11803
Apache subversion: CVE-2018-11803
-advisory.txt [ PGP ] 1.10.0-1.10.3 and 1.11.0 Subversion's mod_dav_svn Apache HTTPD module will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.
GHSA
GHSA-q2m4-jgq9-q8vh: Subversion's mod_dav_svn Apache HTTPD module versions 1
ghsa_unreviewed·2022-05-13
CVE-2018-11803 [HIGH] CWE-824 GHSA-q2m4-jgq9-q8vh: Subversion's mod_dav_svn Apache HTTPD module versions 1
Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.
OSV
CVE-2018-11803: Subversion's mod_dav_svn Apache HTTPD module versions 1
osv·2019-02-05·CVSS 7.5
CVE-2018-11803 [HIGH] CVE-2018-11803: Subversion's mod_dav_svn Apache HTTPD module versions 1
Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-11803 subversion: malicious SVN clients can crash mod_dav_svn [fedora-all]
bugzilla·2019-01-31·CVSS 7.5
CVE-2018-11803 [HIGH] CVE-2018-11803 subversion: malicious SVN clients can crash mod_dav_svn [fedora-all]
CVE-2018-11803 subversion: malicious SVN clients can crash mod_dav_svn [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2018-11803 subversion: malicious SVN clients can crash mod_dav_svn
bugzilla·2019-01-23·CVSS 7.5
CVE-2018-11803 [HIGH] CVE-2018-11803 subversion: malicious SVN clients can crash mod_dav_svn
CVE-2018-11803 subversion: malicious SVN clients can crash mod_dav_svn
Subversion 1.10.0 introduced server-side support for recursive directory listing operations. The implementation in mod_dav_svn failed to validate the root path of the directory listing provided by the client. If the client omits the root path, mod_dav_svn will deference an uninitialized pointer variable and crash the HTTPD worker process handling the request.
References:
https://subversion.apache.org/security/CVE-2018-11803-advisory.txt
Discussion:
Created subversion tracking bugs for this issue:
Affects: fedora-all [bug 1671271]
---
Statement:
This issue did not affect the versions of subversion as shipped with Red Hat Enterprise Linux 5, 6, and 7.
This issue does not affect any Ansible Tower supported versio
http://www.securityfocus.com/bid/106770https://lists.apache.org/thread.html/fa71074862373c142d264534385f8ea5d8d6b80d27f36f3c46f55003%40%3Cdev.subversion.apache.org%3Ehttps://security.gentoo.org/glsa/201904-08https://usn.ubuntu.com/3869-1/http://www.securityfocus.com/bid/106770https://lists.apache.org/thread.html/fa71074862373c142d264534385f8ea5d8d6b80d27f36f3c46f55003%40%3Cdev.subversion.apache.org%3Ehttps://security.gentoo.org/glsa/201904-08https://usn.ubuntu.com/3869-1/
2019-02-05
Published