CVE-2013-4558 Information

Description

The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4 when built with assertions enabled and SVNAutoversioning is enabled allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request as demonstrated using a trailing /.

Reference

http://lists.opensuse.org/opensuse-updates/2013-12/msg00029.html http://lists.opensuse.org/opensuse-updates/2013-12/msg00048.html http://osvdb.org/100363 http://subversion.apache.org/security/CVE-2013-4558-advisory.txt https://bugzilla.redhat.com/show_bug.cgi?id=1033431

Share on: