Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/106770 | Broken Link Third Party Advisory VDB Entry |
https://lists.apache.org/thread.html/fa71074862373c142d264534385f8ea5d8d6b80d27f36f3c46f55003%40%3Cdev.subversion.apache.org%3E | |
https://security.gentoo.org/glsa/201904-08 | Third Party Advisory |
https://usn.ubuntu.com/3869-1/ | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2019-02-05 17:29
Updated : 2023-11-07 02:51
NVD link : CVE-2018-11803
Mitre link : CVE-2018-11803
CVE.ORG link : CVE-2018-11803
JSON object : View
Products Affected
canonical
- ubuntu_linux
apache
- subversion
CWE
CWE-824
Access of Uninitialized Pointer