The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request, as demonstrated using a trailing /.
2013-12-07T20:55:02.553
2025-04-11T00:51:21.963
Deferred
CVSSv2: 3.5 (LOW)
AV:N/AC:M/Au:S/C:N/I:N/A:P
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | mod_dav_svn | - | Yes |
Application | apache | subversion | 1.7.11 | Yes |
Application | apache | subversion | 1.7.12 | Yes |
Application | apache | subversion | 1.7.13 | Yes |
Application | apache | subversion | 1.8.1 | Yes |
Application | apache | subversion | 1.8.2 | Yes |
Application | apache | subversion | 1.8.3 | Yes |
Application | apache | subversion | 1.8.4 | Yes |