IM
IronMonkey Threat Research

CVE-2019-0203 HIGH

Published: 2019-09-26 | Last Modified: 2026-06-17 | Status: Modified

Description

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server.

Additional Descriptions (1)

En Apache Subversion versiones hasta 1.9.10, 1.10.4, 1.12.0 incluyéndolas, el proceso del servidor svnserve de Subversion puede cerrarse cuando un cliente envía determinadas secuencias de comandos de protocolo. Esto puede conllevar a interrupciones para los usuarios del servidor.

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 3.6

Base Score: 5.0 (MEDIUM)

AV:N/AC:L/Au:N/C:N/I:N/A:P

Access VectorNETWORK
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 10.0

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Primary
en CWE-476
en CWE-755

Affected Products

Vendor Product Version Update Type
apache subversion * <built-in method update of dict object at 0x7e60e846f880> Application
apache subversion * <built-in method update of dict object at 0x7e61079c9780> Application
apache subversion * <built-in method update of dict object at 0x7e6107e51c40> Application
apache subversion 1.12.0 <built-in method update of dict object at 0x7e60bae4b640> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:apache:subversion:1.12.0:*:*:*:*:*:*:*

References

Notification
Message here