Lucene search

K
cve[email protected]CVE-2011-1783
HistoryJun 06, 2011 - 7:55 p.m.

CVE-2011-1783

2011-06-0619:55:01
web.nvd.nist.gov
60
apache
mod_dav_svn
http server
cve-2011-1783
denial of service
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.2 Medium

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.6%

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data.

Affected configurations

NVD
Node
apachesubversionRange1.5.0–1.5.8
OR
apachesubversionRange1.6.0–1.6.17
Node
canonicalubuntu_linuxMatch10.04-
OR
canonicalubuntu_linuxMatch10.10
OR
canonicalubuntu_linuxMatch11.04
Node
debiandebian_linuxMatch5.0
OR
debiandebian_linuxMatch6.0
Node
fedoraprojectfedoraMatch14
OR
fedoraprojectfedoraMatch15
Node
applemac_os_xRange<10.7.3

References

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.2 Medium

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.6%