PublicDateAtUSN: 2013-05-02 Candidate: CVE-2013-1884 PublicDate: 2013-05-02 14:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1884 http://subversion.apache.org/security/CVE-2013-1884-advisory.txt https://ubuntu.com/security/notices/USN-1893-1 Description: The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variable. Ubuntu-Description: Notes: mdeslaur> 1.7.0+ Bugs: Priority: medium Discovered-by: Greg McMullin, Stefan Fuhrmann, Philip Martin and Ben Reser Assigned-to: mdeslaur CVSS: Patches_subversion: upstream: http://svn.apache.org/viewvc?view=revision&revision=1462332 Tags_subversion: universe-binary upstream_subversion: released (1.7.9) hardy_subversion: not-affected (1.4.6dfsg1-2ubuntu1.3) lucid_subversion: not-affected (1.6.6dfsg-2ubuntu1.3) oneiric_subversion: not-affected (1.6.12dfsg-4ubuntu5.1) precise_subversion: not-affected (1.6.17dfsg-3ubuntu3) quantal_subversion: released (1.7.5-1ubuntu2.1) raring_subversion: released (1.7.5-1ubuntu3.1) devel_subversion: not-affected (1.7.9-1+nmu2ubuntu2)