7.8 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:N/I:N/A:C
6.6 Medium
AI Score
Confidence
Low
0.112 Low
EPSS
Percentile
95.2%
Alexander Klink discovered that the Subversion mod_dav_svn module for
Apache did not properly handle a large number of properties. A remote
authenticated attacker could use this flaw to cause memory consumption,
leading to a denial of service. (CVE-2013-1845)
Ben Reser discovered that the Subversion mod_dav_svn module for
Apache did not properly handle certain LOCKs. A remote authenticated
attacker could use this flaw to cause Subversion to crash, leading to a
denial of service. (CVE-2013-1846)
Philip Martin and Ben Reser discovered that the Subversion mod_dav_svn
module for Apache did not properly handle certain LOCKs. A remote
attacker could use this flaw to cause Subversion to crash, leading to a
denial of service. (CVE-2013-1847)
It was discovered that the Subversion mod_dav_svn module for Apache did not
properly handle certain PROPFIND requests. A remote attacker could use this
flaw to cause Subversion to crash, leading to a denial of service.
(CVE-2013-1849)
Greg McMullin, Stefan Fuhrmann, Philip Martin, and Ben Reser discovered
that the Subversion mod_dav_svn module for Apache did not properly handle
certain log REPORT requests. A remote attacker could use this flaw to cause
Subversion to crash, leading to a denial of service. This issue only
affected Ubuntu 12.10 and Ubuntu 13.04. (CVE-2013-1884)
Stefan Sperling discovered that Subversion incorrectly handled newline
characters in filenames. A remote authenticated attacker could use this
flaw to corrupt FSFS repositories. (CVE-2013-1968)
Boris Lytochkin discovered that Subversion incorrectly handled TCP
connections that were closed early. A remote attacker could use this flaw
to cause Subversion to crash, leading to a denial of service.
(CVE-2013-2112)
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Ubuntu | 13.04 | noarch | libapache2-svn | < 1.7.5-1ubuntu3.1 | UNKNOWN |
Ubuntu | 13.04 | noarch | libsvn-dev | < 1.7.5-1ubuntu3.1 | UNKNOWN |
Ubuntu | 13.04 | noarch | libsvn-java | < 1.7.5-1ubuntu3.1 | UNKNOWN |
Ubuntu | 13.04 | noarch | libsvn-perl | < 1.7.5-1ubuntu3.1 | UNKNOWN |
Ubuntu | 13.04 | noarch | libsvn1 | < 1.7.5-1ubuntu3.1 | UNKNOWN |
Ubuntu | 13.04 | noarch | python-subversion | < 1.7.5-1ubuntu3.1 | UNKNOWN |
Ubuntu | 13.04 | noarch | python-subversion-dbg | < 1.7.5-1ubuntu3.1 | UNKNOWN |
Ubuntu | 13.04 | noarch | ruby-svn | < 1.7.5-1ubuntu3.1 | UNKNOWN |
Ubuntu | 13.04 | noarch | subversion | < 1.7.5-1ubuntu3.1 | UNKNOWN |
Ubuntu | 12.10 | noarch | libapache2-svn | < 1.7.5-1ubuntu2.1 | UNKNOWN |