CVE-2018-11803

Severity
7.5HIGH
EPSS
14.0%
top 5.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 5
Latest updateMay 13

Description

Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDapache/subversion1.10.01.10.3+1
CVEListV5apache_software_foundation/apache_subversionApache Subversion 1.11.0, 1.10.0 to 1.10.3
Debiansubversion< 1.10.4-1+3

Also affects: Ubuntu Linux 18.10

🔴Vulnerability Details

3
GHSA
GHSA-q2m4-jgq9-q8vh: Subversion's mod_dav_svn Apache HTTPD module versions 12022-05-13
CVEList
CVE-2018-11803: Subversion's mod_dav_svn Apache HTTPD module versions 12019-02-05
OSV
CVE-2018-11803: Subversion's mod_dav_svn Apache HTTPD module versions 12019-02-05

📋Vendor Advisories

4
Ubuntu
Subversion vulnerability2019-01-24
Red Hat
subversion: malicious SVN clients can crash mod_dav_svn2019-01-18
Debian
CVE-2018-11803: subversion - Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10....2018
Apache
Apache subversion: CVE-2018-11803

💬Community

2
Bugzilla
CVE-2018-11803 subversion: malicious SVN clients can crash mod_dav_svn [fedora-all]2019-01-31
Bugzilla
CVE-2018-11803 subversion: malicious SVN clients can crash mod_dav_svn2019-01-23
CVE-2018-11803 (HIGH CVSS 7.5) | Subversion's mod_dav_svn Apache HTT | cvebase.io