In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server.
En Apache Subversion versiones hasta 1.9.10, 1.10.4, 1.12.0 incluyéndolas, el proceso del servidor svnserve de Subversion puede cerrarse cuando un cliente envía determinadas secuencias de comandos de protocolo. Esto puede conllevar a interrupciones para los usuarios del servidor.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | NONE |
| Availability Impact | HIGH |
AV:N/AC:L/Au:N/C:N/I:N/A:P
| Access Vector | NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | NONE |
| Integrity Impact | NONE |
| Availability Impact | PARTIAL |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-476
en
CWE-755
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| apache | subversion | * | <built-in method update of dict object at 0x7e60e846f880> | Application |
| apache | subversion | * | <built-in method update of dict object at 0x7e61079c9780> | Application |
| apache | subversion | * | <built-in method update of dict object at 0x7e6107e51c40> | Application |
| apache | subversion | 1.12.0 | <built-in method update of dict object at 0x7e60bae4b640> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:apache:subversion:1.12.0:*:*:*:*:*:*:* |