Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-17525

Опубликовано: 10 фев. 2021
Источник: redhat
CVSS3: 7.5

Описание

Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7

A null-pointer-dereference flaw was found in mod_authz_svn of subversion. This flaw allows a remote, unauthenticated attacker to cause a denial of service in some server configurations. The highest threat from this vulnerability is to system availability.

Меры по смягчению последствий

As per upstream "As a workaround, the use of in-repository authz rules files with the AuthzSVNReposRelativeAccessFile can be avoided by switching to an alternative configuration which fetches an authz rules file from the server's filesystem, rather than from an SVN repository."

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6subversionNot affected
Red Hat Enterprise Linux 7subversionNot affected
Red Hat Enterprise Linux 8subversion:1.14/subversionNot affected
Red Hat Enterprise Linux 9subversionNot affected
Red Hat Enterprise Linux 8subversionFixedRHSA-2021:050715.02.2021
Red Hat Enterprise Linux 8.1 Extended Update SupportsubversionFixedRHSA-2021:050915.02.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportsubversionFixedRHSA-2021:050815.02.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1922303subversion: Remote unauthenticated denial of service in mod_authz_svn

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7

CVSS3: 7.5
nvd
больше 4 лет назад

Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7

CVSS3: 7.5
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 4 лет назад

Subversion's mod_authz_svn module will crash if the server is using in ...

suse-cvrf
больше 4 лет назад

Security update for subversion

7.5 High

CVSS3