==================================================================== CERT-Renater Note d'Information No. 2019/VULN018 _____________________________________________________________________ DATE : 29/01/2019 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Apache Subversion versions prior to 1.10.4, 1.11.1. ===================================================================== https://mail-archives.apache.org/mod_mbox/subversion-announce/201901.mbox/%3c60d59530-6950-35c5-d118-69e5549b7bf1@apache.org%3e _____________________________________________________________________ This is a security notification for Apache Subversion HTTP Servers: CVE-2018-11803 Severity: Medium Affected Versions: Apache Subversion 1.11.0, 1.10.0 to 1.10.3 Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation. This issue can be triggered by any client on Subversion repositories configured for anonymous read access. If read access requires authentication, a denial of service attack can only be performed by an authenticated user. The Subversion releases 1.10.4 and 1.11.1 contain the fixes for this vulnerability and are available immediately at: https://dist.apache.org/repos/dist/release/subversion/?p=32084 Additional details, including patches for 1.10.3 and 1.11.0 can be found at: https://subversion.apache.org/security/CVE-2018-11803-advisory.txt We encourage users of Subversion to upgrade to the latest appropriate version as soon as reasonable. Thanks, - The Subversion Team ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================