CVE-2018-11803

Name
CVE-2018-11803
Description
Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Mailing List https://lists.apache.org/thread.html/fa71074862373c142d264534385f8ea5d8d6b80d27f36f3c46f55003@%3Cdev.subversion.apache.org%3E
Third Party Advisory https://usn.ubuntu.com/3869-1/
Third Party Advisory http://www.securityfocus.com/bid/106770
GENTOO https://security.gentoo.org/glsa/201904-08

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:* subversion >= 1.10.0 <= 1.10.3
cpe:2.3:a:apache:subversion:1.11.0:*:*:*:*:*:*:* subversion == None == 1.11.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status