Severity
7.5HIGH
EPSS
6.6%
top 8.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 26
Latest updateMay 26

Description

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDapache/subversion1.10.01.10.4+3
CVEListV5apache_subversionApache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0
Debiansubversion< 1.10.6-1+3
Ubuntusubversion< 1.9.3-2ubuntu1.3

Patches

🔴Vulnerability Details

5
OSV
subversion vulnerabilities2022-05-26
GHSA
GHSA-2wxr-pw8w-8wx5: In Apache Subversion versions up to and including 12022-05-24
OSV
CVE-2019-0203: In Apache Subversion versions up to and including 12019-09-26
CVEList
CVE-2019-0203: In Apache Subversion versions up to and including 12019-09-26
OSV
subversion vulnerabilities2019-07-31

📋Vendor Advisories

6
Ubuntu
Subversion vulnerabilities2022-05-26
Red Hat
subversion: NULL pointer dereference in svnserve leading to an unauthenticated remote DoS2019-07-31
Ubuntu
Subversion vulnerabilities2019-07-31
Ubuntu
Subversion vulnerabilities2019-07-31
Debian
CVE-2019-0203: subversion - In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subver...2019

💬Community

2
Bugzilla
CVE-2019-0203 subversion: remote unauthenticated denial-of-service in subversion svnserve [fedora-all]2019-08-01
Bugzilla
CVE-2019-0203 subversion: NULL pointer dereference in svnserve leading to an unauthenticated remote DoS2019-07-25
CVE-2019-0203 (HIGH CVSS 7.5) | In Apache Subversion versions up to | cvebase.io