CVE-2014-0032

Priority
Medium
Description
The get_resource function in repos.c in the mod_dav_svn module in Apache
Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is
enabled, allows remote attackers to cause a denial of service (crash) via
vectors related to the server root and request methods other than GET, as
demonstrated by the "svn ls http://svn.example.com" command.
References
Bugs
Assigned-to
mdeslaur
Package
Upstream:released (1.7.14,1.8.8)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):released (1.6.17dfsg-3ubuntu3.4)
Ubuntu 14.04 LTS (Trusty Tahr):not-affected (1.8.8-1ubuntu3)
Ubuntu 14.10 (Utopic Unicorn):not-affected (1.8.8-1ubuntu3)
Patches:
Upstream:http://svn.apache.org/viewvc?view=revision&revision=r1557320
Upstream:http://svn.apache.org/viewvc?view=revision&revision=1558692 (1.7.x)
More Information

Valid XHTML 1.0 Strict

Updated: 2014-08-14 19:14:34 UTC (commit 8374)