Lucene search

K
cveRedhatCVE-2014-0032
HistoryFeb 14, 2014 - 3:55 p.m.

CVE-2014-0032

2014-02-1415:55:05
CWE-20
redhat
web.nvd.nist.gov
62
cve-2014-0032
mod_dav_svn
apache subversion
denial of service
remote attackers
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

7.9

Confidence

High

EPSS

0.1

Percentile

95.0%

The get_resource function in repos.c in the mod_dav_svn module in Apache Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is enabled, allows remote attackers to cause a denial of service (crash) via vectors related to the server root and request methods other than GET, as demonstrated by the “svn ls http://svn.example.com” command.

Affected configurations

Nvd
Node
apachesubversionMatch1.8.0
OR
apachesubversionMatch1.8.1
OR
apachesubversionMatch1.8.2
OR
apachesubversionMatch1.8.3
OR
apachesubversionMatch1.8.4
OR
apachesubversionMatch1.8.5
Node
apachesubversionRange1.7.14
OR
apachesubversionMatch1.7.0
OR
apachesubversionMatch1.7.1
OR
apachesubversionMatch1.7.2
OR
apachesubversionMatch1.7.3
OR
apachesubversionMatch1.7.4
OR
apachesubversionMatch1.7.5
OR
apachesubversionMatch1.7.6
OR
apachesubversionMatch1.7.7
OR
apachesubversionMatch1.7.8
OR
apachesubversionMatch1.7.9
OR
apachesubversionMatch1.7.10
OR
apachesubversionMatch1.7.11
OR
apachesubversionMatch1.7.12
OR
apachesubversionMatch1.7.13
VendorProductVersionCPE
apachesubversion1.8.0cpe:2.3:a:apache:subversion:1.8.0:*:*:*:*:*:*:*
apachesubversion1.8.1cpe:2.3:a:apache:subversion:1.8.1:*:*:*:*:*:*:*
apachesubversion1.8.2cpe:2.3:a:apache:subversion:1.8.2:*:*:*:*:*:*:*
apachesubversion1.8.3cpe:2.3:a:apache:subversion:1.8.3:*:*:*:*:*:*:*
apachesubversion1.8.4cpe:2.3:a:apache:subversion:1.8.4:*:*:*:*:*:*:*
apachesubversion1.8.5cpe:2.3:a:apache:subversion:1.8.5:*:*:*:*:*:*:*
apachesubversion*cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:*
apachesubversion1.7.0cpe:2.3:a:apache:subversion:1.7.0:*:*:*:*:*:*:*
apachesubversion1.7.1cpe:2.3:a:apache:subversion:1.7.1:*:*:*:*:*:*:*
apachesubversion1.7.2cpe:2.3:a:apache:subversion:1.7.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 211

References

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

7.9

Confidence

High

EPSS

0.1

Percentile

95.0%