CVE-2018-11782
subversion: remotely triggerable DoS vulnerability in svnserve 'get-deleted-rev'
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server.
En Apache Subversion versiones hasta 1.9.10, 1.10.4, 1.12.0 incluyéndolas, el proceso del servidor svnserve de Subversion puede cerrarse cuando una petición de solo lectura bien formada produce una respuesta en particular. Esto puede conllevar a interrupciones para usuarios del servidor.
Ace Olszowka discovered that Subversion incorrectly handled certain svnserve requests. A remote attacker could possibly use this issue to cause svnserver to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS. Tomas Bortoli discovered that Subversion incorrectly handled certain svnserve requests. A remote attacker could possibly use this issue to cause svnserver to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-06-05 CVE Reserved
- 2019-07-31 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-617: Reachable Assertion
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://subversion.apache.org/security/CVE-2018-11782-advisory.txt | 2019-09-27 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2018-11782 | 2020-11-04 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1733088 | 2020-11-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Subversion Search vendor "Apache" for product "Subversion" | <= 1.9.10 Search vendor "Apache" for product "Subversion" and version " <= 1.9.10" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Subversion Search vendor "Apache" for product "Subversion" | >= 1.10.0 <= 1.10.4 Search vendor "Apache" for product "Subversion" and version " >= 1.10.0 <= 1.10.4" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Subversion Search vendor "Apache" for product "Subversion" | >= 1.11.0 <= 1.11.1 Search vendor "Apache" for product "Subversion" and version " >= 1.11.0 <= 1.11.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Subversion Search vendor "Apache" for product "Subversion" | 1.12.0 Search vendor "Apache" for product "Subversion" and version "1.12.0" | - |
Affected
|