IM
IronMonkey Threat Research

CVE-2018-11782 MEDIUM

Published: 2019-09-26 | Last Modified: 2026-06-17 | Status: Modified

Description

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server.

Additional Descriptions (1)

En Apache Subversion versiones hasta 1.9.10, 1.10.4, 1.12.0 incluyéndolas, el proceso del servidor svnserve de Subversion puede cerrarse cuando una petición de solo lectura bien formada produce una respuesta en particular. Esto puede conllevar a interrupciones para usuarios del servidor.

CVSS Metrics

Base Score: 6.5 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 2.8

Impact Score: 3.6

Base Score: 4.0 (MEDIUM)

AV:N/AC:L/Au:S/C:N/I:N/A:P

Access VectorNETWORK
Access ComplexityLOW
AuthenticationSINGLE
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 8.0

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Primary
en CWE-20

Affected Products

Vendor Product Version Update Type
apache subversion * <built-in method update of dict object at 0x7e6110a54400> Application
apache subversion * <built-in method update of dict object at 0x7e611239dd40> Application
apache subversion * <built-in method update of dict object at 0x7e6110a559c0> Application
apache subversion 1.12.0 <built-in method update of dict object at 0x7e60e86cc800> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:apache:subversion:1.12.0:*:*:*:*:*:*:*

References

Notification
Message here