CVE-2019-0203
published 2019-09-26CVE-2019-0203: In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.44%
87.6th percentile
In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | <= 1.9.10 | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.10.6-1 | 1.10.6-1 |
| apache | subversion | >= 0 < 1.10.6-1 | 1.10.6-1 |
| apache | subversion | >= 0 < 1.10.6-1 | 1.10.6-1 |
| apache | subversion | >= 0 < 1.10.6-1 | 1.10.6-1 |
| apache | subversion | >= 0 < 1.9.3-2ubuntu1.3 | 1.9.3-2ubuntu1.3 |
| apache | subversion | >= 0 < 1.9.7-4ubuntu1.1 | 1.9.7-4ubuntu1.1 |
| apache | subversion | >= 0 < 1.13.0-3ubuntu0.2 | 1.13.0-3ubuntu0.2 |
| apache | subversion | 1.10.0 – 1.10.4 | — |
| apache | subversion | 1.11.0 – 1.11.1 | — |
| debian | subversion | < subversion 1.10.6-1 (bookworm) | subversion 1.10.6-1 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2022-05-26·CVSS 6.5
CVE-2020-17525 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Several security issues were fixed in subversion.
Ace Olszowka discovered that Subversion incorrectly handled certain
svnserve requests. A remote attacker could possibly use this issue to cause
svnserver to crash, resulting in a denial of service. This issue only
affected Ubuntu 18.04 LTS. (CVE-2018-11782)
Tomas Bortoli discovered that Subversion incorrectly handled certain
svnserve requests. A remote attacker could possibly use this issue to cause
svnserver to crash, resulting in a denial of service. This issue only
affected Ubuntu 18.04 LTS. (CVE-2019-0203)
Thomas Åkesson discovered that Subversion incorrectly handled certain
inputs. An attacker could possibly use this issue to cause a denial of
service. (CVE-2020-17525)
Instructions: In ge
CISA ICS
Yokogawa CENTUM and ProSafe-RS
cisa_ics·2022-05-03·CVSS 5.0
[MEDIUM] Yokogawa CENTUM and ProSafe-RS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Yokogawa CENTUM and ProSafe-RS
Last RevisedMay 03, 2022
Alert CodeICSA-22-123-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Yokogawa
- Equipment: CENTUM and ProSafe-RS
- Vulnerabilities: OS Command Injection, Improper Authentication, NULL Pointer Dereference, Improper Input Validation, Resource Management Errors
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allow leakage/tampering of data, cause a denial-of-service condition, or allow a local attacker to execute arbitrary programs.
#
Red Hat
subversion: NULL pointer dereference in svnserve leading to an unauthenticated remote DoS
vendor_redhat·2019-07-31·CVSS 7.5
CVE-2019-0203 [HIGH] CWE-476 subversion: NULL pointer dereference in svnserve leading to an unauthenticated remote DoS
subversion: NULL pointer dereference in svnserve leading to an unauthenticated remote DoS
In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server.
A flaw was found in subversion. A remote, unauthenticated user can cause a null-pointer-dereference in svnserve by sending a certain sequences of protocol commands to the server. This results in a denial of service in some server configurations, specifically when anonymous access is enabled. The highest threat from this vulnerability is to system availability.
Package: subversion (Red Hat Enterprise Linux 5) - Not affected
Package: subversion (Red Hat Enterprise Linux
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2019-07-31·CVSS 6.5
CVE-2018-11782 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Subversion could be made to crash if it received specially crafted network
traffic.
USN-4082-1 fixed several vulnerabilities in Subversion. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Ace Olszowka discovered that Subversion incorrectly handled certain
svnserve requests. A remote attacker could possibly use this issue to
cause svnserver to crash, resulting in a denial of service.
(CVE-2018-11782)
Tomas Bortoli discovered that Subversion incorrectly handled certain
svnserve requests. A remote attacker could possibly use this issue to
cause svnserver to crash, resulting in a denial of service. (CVE-2019-0203)
Instructions: In general, a standard system update will make all the necessary changes
Ubuntu
Subversion vulnerabilities
vendor_ubuntu·2019-07-31·CVSS 6.5
CVE-2018-11782 [MEDIUM] Subversion vulnerabilities
Title: Subversion vulnerabilities
Summary: Subversion could be made to crash if it received specially crafted network
traffic.
Ace Olszowka discovered that Subversion incorrectly handled certain
svnserve requests. A remote attacker could possibly use this issue to
cause svnserver to crash, resulting in a denial of service.
(CVE-2018-11782)
Tomas Bortoli discovered that Subversion incorrectly handled certain
svnserve requests. A remote attacker could possibly use this issue to
cause svnserver to crash, resulting in a denial of service. (CVE-2019-0203)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-0203: subversion - In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subver...
vendor_debian·2019·CVSS 7.5
CVE-2019-0203 [HIGH] CVE-2019-0203: subversion - In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subver...
In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server.
Scope: local
bookworm: resolved (fixed in 1.10.6-1)
bullseye: resolved (fixed in 1.10.6-1)
forky: resolved (fixed in 1.10.6-1)
sid: resolved (fixed in 1.10.6-1)
trixie: resolved (fixed in 1.10.6-1)
Apache
Apache subversion: CVE-2019-0203
vendor_apache·CVSS 7.5
CVE-2019-0203 [HIGH] Apache subversion: CVE-2019-0203
Apache subversion: CVE-2019-0203
-advisory.txt [ PGP ] 1.9.0-1.9.10, 1.10.0-1.10.4, 1.11.0-1.11.1, 1.12.0 Remote unauthenticated denial-of-service in Subversion svnserve.
OSV
subversion vulnerabilities
osv·2022-05-26·CVSS 6.5
CVE-2018-11782 [MEDIUM] subversion vulnerabilities
subversion vulnerabilities
Ace Olszowka discovered that Subversion incorrectly handled certain
svnserve requests. A remote attacker could possibly use this issue to cause
svnserver to crash, resulting in a denial of service. This issue only
affected Ubuntu 18.04 LTS. (CVE-2018-11782)
Tomas Bortoli discovered that Subversion incorrectly handled certain
svnserve requests. A remote attacker could possibly use this issue to cause
svnserver to crash, resulting in a denial of service. This issue only
affected Ubuntu 18.04 LTS. (CVE-2019-0203)
Thomas Åkesson discovered that Subversion incorrectly handled certain
inputs. An attacker could possibly use this issue to cause a denial of
service. (CVE-2020-17525)
GHSA
GHSA-2wxr-pw8w-8wx5: In Apache Subversion versions up to and including 1
ghsa_unreviewed·2022-05-24
CVE-2019-0203 [HIGH] CWE-20 GHSA-2wxr-pw8w-8wx5: In Apache Subversion versions up to and including 1
In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server.
OSV
CVE-2019-0203: In Apache Subversion versions up to and including 1
osv·2019-09-26·CVSS 7.5
CVE-2019-0203 [HIGH] CVE-2019-0203: In Apache Subversion versions up to and including 1
In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server.
OSV
subversion vulnerabilities
osv·2019-07-31·CVSS 6.5
CVE-2018-11782 [MEDIUM] subversion vulnerabilities
subversion vulnerabilities
Ace Olszowka discovered that Subversion incorrectly handled certain
svnserve requests. A remote attacker could possibly use this issue to
cause svnserver to crash, resulting in a denial of service.
(CVE-2018-11782)
Tomas Bortoli discovered that Subversion incorrectly handled certain
svnserve requests. A remote attacker could possibly use this issue to
cause svnserver to crash, resulting in a denial of service. (CVE-2019-0203)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-0203 subversion: remote unauthenticated denial-of-service in subversion svnserve [fedora-all]
bugzilla·2019-08-01·CVSS 7.5
CVE-2019-0203 [HIGH] CVE-2019-0203 subversion: remote unauthenticated denial-of-service in subversion svnserve [fedora-all]
CVE-2019-0203 subversion: remote unauthenticated denial-of-service in subversion svnserve [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mu
Bugzilla
CVE-2019-0203 subversion: NULL pointer dereference in svnserve leading to an unauthenticated remote DoS
bugzilla·2019-07-25·CVSS 7.5
CVE-2019-0203 [HIGH] CVE-2019-0203 subversion: NULL pointer dereference in svnserve leading to an unauthenticated remote DoS
CVE-2019-0203 subversion: NULL pointer dereference in svnserve leading to an unauthenticated remote DoS
Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server. A null-pointer-dereference in svnserve results in a remote unauthenticated Denial-of-Service in some server configurations. The vulnerability can be triggered by an unauthenticated user if the server is configured with anonymous access enabled.
The problem originates in opening a new connection to svnserve. On failure to find the specified repository or to be authorized to access it, svnserve logs and reports the error, but also keeps the connection open despite its incomplete initialization. If the client sends any further comma
2019-09-26
Published