CVE-2016-2168

Priority
Medium
Description
The req_check_access function in the mod_authz_svn module in the httpd
server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows
remote authenticated users to cause a denial of service (NULL pointer
dereference and crash) via a crafted header in a (1) MOVE or (2) COPY
request, involving an authorization check.
References
Package
Upstream:released (1.9.4-1)
Ubuntu 17.10 (Artful Aardvark):not-affected (1.9.4-1ubuntu1)
Ubuntu 12.04 ESM (Precise Pangolin):released (1.6.17dfsg-3ubuntu3.7)
Ubuntu 14.04 LTS (Trusty Tahr):released (1.8.8-1ubuntu3.3)
Ubuntu 16.04 LTS (Xenial Xerus):released (1.9.3-2ubuntu1.1)
Ubuntu 17.04 (Zesty Zapus):not-affected (1.9.4-1ubuntu1)
More Information

Updated: 2017-10-24 18:14:14 UTC (commit 13579)