CVE-2014-0032 (retired)

Priority
Description
The get_resource function in repos.c in the mod_dav_svn module in Apache
Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is
enabled, allows remote attackers to cause a denial of service (crash) via
vectors related to the server root and request methods other than GET, as
demonstrated by the "svn ls http://svn.example.com" command.
Assigned-to
mdeslaur
Package
Upstream:released (1.7.14,1.8.8)
Ubuntu 14.04 ESM (Trusty Tahr):not-affected (1.8.8-1ubuntu3)
Patches:
Upstream:http://svn.apache.org/viewvc?view=revision&revision=r1557320
Upstream:http://svn.apache.org/viewvc?view=revision&revision=1558692 (1.7.x)
Binaries built from this source package are in universe and so are supported by the community. For more details see https://wiki.ubuntu.com/SecurityTeam/FAQ#Official_Support
More Information

Updated: 2019-09-19 15:46:55 UTC (commit d32ebc32606b9517c6fa7d65a15441e2a57a6de5)