Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-24070

Опубликовано: 04 нояб. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do not use mod_dav_svn are not affected.

A use-after-free vulnerability was found in Subversion in the mod_dav_svn Apache HTTP server (HTTPd) module. While looking up path-based authorization (authz) rules, multiple calls to the post_config hook can invalidate cached pointers to object-pools, which Subversion subsequently uses. This issue crashes the single HTTPd worker thread or the entire HTTPd server process, depending on the configuration of the Apache HTTPd server.

Отчет

The vulnerable code was introduced in Subversion 1.10 as part of a new implementation of path-based authorization (authz). Red Hat Enterprise Linux 6 and 7 are not affected by this flaw as they ship an older version of Subversion.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6subversionNot affected
Red Hat Enterprise Linux 7subversionNot affected
Red Hat Enterprise Linux 8subversionFixedRHSA-2022:223412.05.2022
Red Hat Enterprise Linux 8subversionFixedRHSA-2022:494108.06.2022
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionssubversionFixedRHSA-2022:223712.05.2022
Red Hat Enterprise Linux 8.2 Extended Update SupportsubversionFixedRHSA-2022:223612.05.2022
Red Hat Enterprise Linux 8.4 Extended Update SupportsubversionFixedRHSA-2022:222211.05.2022
Red Hat Enterprise Linux 8.4 Extended Update SupportsubversionFixedRHSA-2022:472224.05.2022
Red Hat Enterprise Linux 9subversionFixedRHSA-2022:459118.05.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2074772subversion: Subversion's mod_dav_svn is vulnerable to memory corruption

EPSS

Процентиль: 59%
0.00387
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do not use mod_dav_svn are not affected.

CVSS3: 7.5
nvd
больше 3 лет назад

Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do not use mod_dav_svn are not affected.

CVSS3: 7.5
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 3 лет назад

Subversion's mod_dav_svn is vulnerable to memory corruption. While loo ...

rocky
около 3 лет назад

Important: subversion:1.14 security update

EPSS

Процентиль: 59%
0.00387
Низкий

7.5 High

CVSS3