cbcvebase.

Debian Subversion vulnerabilities

51 known vulnerabilities affecting debian/subversion.

Total CVEs
51
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH10MEDIUM22LOW17

Vulnerabilities

Page 2 of 3
CVE-2018-11782P3MEDIUMCVSS 6.5fixed in subversion 1.10.6-1 (bookworm)2018
CVE-2018-11782 [MEDIUM] CVE-2018-11782: subversion - In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subver... In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server. Scope: local bookworm: resolved (fixed in 1.10.6-1) bullseye: resolved (fixed in 1.10.6-1) forky: resolved (fixed in 1.10.6
debian
CVE-2016-8734P3LOWCVSS 6.5fixed in subversion 1.9.5-1 (bookworm)2016
CVE-2016-8734 [MEDIUM] CVE-2016-8734: subversion - Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16,... Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory. Scope: local bookworm: resolved (fixed in 1.9.5-1) bullseye: resolved
debian
CVE-2015-0248P4MEDIUMCVSS 5.0fixed in subversion 1.8.10-6 (bookworm)2015
CVE-2015-0248 [MEDIUM] CVE-2015-0248: subversion - The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 ... The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and abort) via crafted parameter combinations related to dynamically evaluated revision numbers. Scope: local bookworm: resolved (fixed in 1.8.10-6) bullseye: resolved (fixed in 1.8.10-6) f
debian
CVE-2014-8108P4MEDIUMCVSS 5.0fixed in subversion 1.8.10-5 (bookworm)2014
CVE-2014-8108 [MEDIUM] CVE-2014-8108: subversion - The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7... The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request for a URI that triggers a lookup for a virtual transaction name that does not exist. Scope: local bookworm: resolved (fixed in 1.8.10-5) bullseye: resolv
debian
CVE-2014-3580P4MEDIUMCVSS 5.0fixed in subversion 1.8.10-5 (bookworm)2014
CVE-2014-3580 [MEDIUM] CVE-2014-3580: subversion - The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.1... The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist. Scope: local bookworm: resolved (fixed in 1.8.10-5) bullseye: resolved (fixed in 1.8.10-5) forky: resolve
debian
CVE-2010-4539P4LOWCVSS 6.8fixed in subversion 1.6.12dfsg-4 (bookworm)2010
CVE-2010-4539 [MEDIUM] CVE-2010-4539: subversion - The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Serve... The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.15, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger the walking of SVNParentPath collections. Scope: local bookworm: resolved (fixed in 1.6.12dfsg-4) b
debian
CVE-2014-3528P4LOWCVSS 4.0fixed in subversion 1.8.10-1 (bookworm)2014
CVE-2014-3528 [MEDIUM] CVE-2014-3528: subversion - Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses... Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm. Scope: local bookworm: resolved (fixed in 1.8.10-1) bullseye: resolved (fixed in 1.8.10-1) forky: resolv
debian
CVE-2014-0032P4LOWCVSS 4.3fixed in subversion 1.8.8-1 (bookworm)2014
CVE-2014-0032 [MEDIUM] CVE-2014-0032: subversion - The get_resource function in repos.c in the mod_dav_svn module in Apache Subvers... The get_resource function in repos.c in the mod_dav_svn module in Apache Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is enabled, allows remote attackers to cause a denial of service (crash) via vectors related to the server root and request methods other than GET, as demonstrated by the "svn ls http://svn.example.com" command. Scope: l
debian
CVE-2015-0251P4MEDIUMCVSS 4.0fixed in subversion 1.8.10-6 (bookworm)2015
CVE-2015-0251 [MEDIUM] CVE-2015-0251: subversion - The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.... The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences. Scope: local bookworm: resolved (fixed in 1.8.10-6) bullseye: resolved (fixed in 1.8.10-6) forky: resolved (fixed in 1.8.10-6) sid: resolved (fixed in 1.8.10-6) trix
debian
CVE-2013-1849P4MEDIUMCVSS 4.3fixed in subversion 1.7.9-1 (bookworm)2013
CVE-2013-1849 [MEDIUM] CVE-2013-1849: subversion - The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 an... The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL. Scope: local bookworm: resolved (fixed in 1.7.9-1) bullseye: resolved (fixed in 1.7.9-1) forky: resolved (fixed in 1.7.9-1) sid:
debian
CVE-2011-1921P4MEDIUMCVSS 4.3fixed in subversion 1.6.17dfsg-1 (bookworm)2011
CVE-2011-1921 [MEDIUM] CVE-2011-1921: subversion - The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subv... The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation. Scope
debian
CVE-2011-1783P4MEDIUMCVSS 4.3fixed in subversion 1.6.17dfsg-1 (bookworm)2011
CVE-2011-1783 [MEDIUM] CVE-2011-1783: subversion - The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subv... The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data. Scope: local bookworm: resolved (fixed in 1.6.17d
debian
CVE-2021-28544P4MEDIUMCVSS 4.3fixed in subversion 1.14.2-1 (bookworm)2021
CVE-2021-28544 [MEDIUM] CVE-2021-28544: subversion - Apache Subversion SVN authz protected copyfrom paths regression Subversion serve... Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact that the node
debian
CVE-2011-0715P4MEDIUMCVSS 4.3fixed in subversion 1.6.16dfsg-1 (bookworm)2011
CVE-2011-0715 [MEDIUM] CVE-2011-0715: subversion - The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subv... The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token. Scope: local bookworm: resolved (fixed in 1.6.16dfsg-1) bullseye: resolved (fixed in 1.6.16dfsg-1) forky: resolved (fixed in
debian
CVE-2024-46901P4LOWCVSS 3.1fixed in subversion 1.14.2-4+deb12u1 (bookworm)2024
CVE-2024-46901 [LOW] CVE-2024-46901: subversion - Insufficient validation of filenames against control characters in Apache Subver... Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository. All versions of Subversion up to and including Subversion 1.14.4 are affected if serving repositories via mod_dav_sv
debian
CVE-2014-3522P4MEDIUMCVSS 4.0fixed in subversion 1.8.10-1 (bookworm)2014
CVE-2014-3522 [MEDIUM] CVE-2014-3522: subversion - The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8... The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate. Scope: local bookworm: resolved (fixed in 1.8.10-1) bullseye: resolved (fi
debian
CVE-2015-3187P4MEDIUMCVSS 4.0fixed in subversion 1.9.0-1 (bookworm)2015
CVE-2015-3187 [MEDIUM] CVE-2015-3187: subversion - The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 a... The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has been moved from a hidden path. Scope: local bookworm: resolved (fixed in 1.9.0-1) bullseye: resolved (fixed i
debian
CVE-2013-1968P4MEDIUMCVSS 5.5fixed in subversion 1.7.9-1+nmu2 (bookworm)2013
CVE-2013-1968 [MEDIUM] CVE-2013-1968: subversion - Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated use... Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name. Scope: local bookworm: resolved (fixed in 1.7.9-1+nmu2) bullseye: resolved (fixed in 1.7.9-1+nmu2) forky: resolved (fixed in 1.7.9-1+nmu2) sid: resolved (fixed in 1.7.9-1+nmu2) trixie:
debian
CVE-2013-1846P4MEDIUMCVSS 4.0fixed in subversion 1.7.9-1 (bookworm)2013
CVE-2013-1846 [MEDIUM] CVE-2013-1846: subversion - The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and... The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a LOCK on an activity URL. Scope: local bookworm: resolved (fixed in 1.7.9-1) bullseye: resolved (fixed in 1.7.9-1) forky: resolved (fixed in 1.7.9-1) sid: reso
debian
CVE-2013-4558P4LOWCVSS 3.5fixed in subversion 1.7.14-1 (bookworm)2013
CVE-2013-4558 [LOW] CVE-2013-4558: subversion - The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server m... The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request, as demonstrated
debian
Debian Subversion vulnerabilities | cvebase