CVE-2014-0032

Priority
Description
The get_resource function in repos.c in the mod_dav_svn module in Apache
Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is
enabled, allows remote attackers to cause a denial of service (crash) via
vectors related to the server root and request methods other than GET, as
demonstrated by the "svn ls http://svn.example.com" command.
Assigned-to
mdeslaur
Notes
Package
Upstream:released (1.7.14,1.8.8)
Ubuntu 14.04 ESM (Trusty Tahr):DNE (trusty was not-affected [1.8.8-1ubuntu3])
Patches:
Upstream:http://svn.apache.org/viewvc?view=revision&revision=r1557320
Upstream:http://svn.apache.org/viewvc?view=revision&revision=1558692 (1.7.x)
Binaries built from this source package are in universe and so are supported by the community. For more details see https://wiki.ubuntu.com/SecurityTeam/FAQ#Official_Support
More Information

Updated: 2020-01-29 19:48:40 UTC (commit 768ceb2fdee6790d707d0f681e1b54916744af1e)