cbcvebase.
CVE-2018-11803
published 2019-02-05

CVE-2018-11803: Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits…

PriorityP357high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
57.82%
99.0th percentile
Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.

Affected

10 ranges
VendorProductVersion rangeFixed in
apachesubversion
apachesubversion
apachesubversion>= 0 < 1.10.4-11.10.4-1
apachesubversion>= 0 < 1.10.4-11.10.4-1
apachesubversion>= 0 < 1.10.4-11.10.4-1
apachesubversion>= 0 < 1.10.4-11.10.4-1
apachesubversion1.10.0 – 1.10.3
apache_software_foundationapache_subversion
canonicalubuntu_linux
debiansubversion< subversion 1.10.4-1 (bookworm)subversion 1.10.4-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered when a malicious SVN client omits the root path in a recursive directory listing operation against mod_dav_svn. Monitor for SVN REPORT requests (used for recursive directory listings) that lack a root path element, which will cause the HTTPD worker process to crash — detectable as an abnormal Apache worker process termination.
  • Affected versions are mod_dav_svn as shipped with Subversion 1.10.0–1.10.3 and 1.11.0. Detection should focus on identifying these specific version strings in deployed Apache HTTPD modules.
  • Subversion 1.10.0 introduced server-side support for recursive directory listing operations — this feature's introduction is the root cause. Environments running Subversion 1.10.0+ with mod_dav_svn exposed to untrusted clients are at risk.
  • ·The vulnerability only affects mod_dav_svn when it is actively loaded and used as an Apache HTTPD module. Subversion deployments not using mod_dav_svn (e.g., svnserve) are not affected.
  • ·Red Hat Enterprise Linux 5, 6, and 7 ship versions of Subversion that are not affected; only RHEL 8 (and Fedora) carry the vulnerable version range.
  • ·The advisory and fix are documented at the Apache Subversion security page; the advisory text (CVE-2018-11803-advisory.txt) and its PGP signature are available for verification.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.