Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.
References
Link | Resource |
---|---|
https://lists.apache.org/thread.html/fa71074862373c142d264534385f8ea5d8d6b80d27f36f3c46f55003@%3Cdev.subversion.apache.org%3E | Mailing List Patch Vendor Advisory |
https://usn.ubuntu.com/3869-1/ | Third Party Advisory |
http://www.securityfocus.com/bid/106770 | Broken Link Third Party Advisory VDB Entry |
https://security.gentoo.org/glsa/201904-08 | Third Party Advisory |
Information
Published : 2019-02-05 09:29
Updated : 2023-03-03 13:00
NVD link : CVE-2018-11803
Mitre link : CVE-2018-11803
JSON object : View
CWE
CWE-824
Access of Uninitialized Pointer
Products Affected
canonical
- ubuntu_linux
apache
- subversion