Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-11782

Опубликовано: 31 июл. 2019
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server.

Отчет

An authenticated user can cause subversion server (svnserve) process to crash by sending a well-formed read-only request which produces a particular answer. Exploitation results in denial of service by crashing an svnserve process. The impact of this differs depending on how svnserve is launched, including the different run modes selected by options such as "svnserve -d", "svnserve -T -d", "svnserve -t", and "svnserve -i". mod_dav_svn is not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5subversionOut of support scope
Red Hat Enterprise Linux 6subversionOut of support scope
Red Hat Enterprise Linux 7subversionFixedRHSA-2020:397229.09.2020
Red Hat Enterprise Linux 8subversionFixedRHSA-2020:471204.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=1733088subversion: remotely triggerable DoS vulnerability in svnserve 'get-deleted-rev'

EPSS

Процентиль: 79%
0.01229
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 6 лет назад

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server.

CVSS3: 6.5
nvd
около 6 лет назад

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server.

CVSS3: 6.5
debian
около 6 лет назад

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12 ...

rocky
около 5 лет назад

Moderate: subversion:1.10 security update

CVSS3: 6.5
github
больше 3 лет назад

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server.

EPSS

Процентиль: 79%
0.01229
Низкий

6.5 Medium

CVSS3