Candidate: CVE-2013-4558 PublicDate: 2013-12-07 20:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4558 http://subversion.apache.org/security/CVE-2013-4558-advisory.txt Description: The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request, as demonstrated using a trailing /. Ubuntu-Description: Notes: mdeslaur> only affects 1.7.11 through 1.7.13 Bugs: Priority: low Discovered-by: Philip Martin Assigned-to: CVSS: Patches_subversion: Tags_subversion: universe-binary upstream_subversion: released (1.7.14,1.8.5) lucid_subversion: ignored (reached end-of-life) precise_subversion: not-affected quantal_subversion: not-affected raring_subversion: not-affected saucy_subversion: not-affected trusty_subversion: not-affected (1.8.8-1ubuntu3) trusty/esm_subversion: DNE (trusty was not-affected [1.8.8-1ubuntu3]) devel_subversion: not-affected (1.8.9-2ubuntu2)