CVE-2020-17525

Name
CVE-2020-17525
Description
Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://subversion.apache.org/security/CVE-2020-17525-advisory.txt
MLIST https://lists.debian.org/debian-lts-announce/2021/05/msg00000.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:* subversion >= 1.9.0 < 1.10.7
cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:* subversion >= 1.11.0 < 1.14.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
subversion edge-main 1.14.1-r0 None fixed
subversion edge-main 1.12.2-r0 None possibly vulnerable
subversion edge-main 1.11.1-r0 None possibly vulnerable
subversion edge-main 1.9.7-r0 None possibly vulnerable
subversion 3.22-main 1.14.1-r0 None fixed
subversion 3.22-main 1.12.2-r0 None possibly vulnerable
subversion 3.22-main 1.11.1-r0 None possibly vulnerable
subversion 3.22-main 1.9.7-r0 None possibly vulnerable
subversion 3.21-main 1.14.1-r0 None fixed
subversion 3.21-main 1.12.2-r0 None possibly vulnerable
subversion 3.21-main 1.11.1-r0 None possibly vulnerable
subversion 3.21-main 1.9.7-r0 None possibly vulnerable
subversion 3.20-main 1.14.1-r0 None fixed
subversion 3.20-main 1.12.2-r0 None possibly vulnerable
subversion 3.20-main 1.11.1-r0 None possibly vulnerable
subversion 3.20-main 1.9.7-r0 None possibly vulnerable
subversion 3.19-main 1.14.1-r0 None fixed
subversion 3.19-main 1.12.2-r0 None possibly vulnerable
subversion 3.19-main 1.11.1-r0 None possibly vulnerable
subversion 3.19-main 1.9.7-r0 None possibly vulnerable
subversion 3.18-main 1.14.1-r0 None fixed
subversion 3.17-main 1.14.1-r0 None fixed
subversion 3.12-main 1.13.0-r3 Natanael Copa <ncopa@alpinelinux.org> fixed
subversion 3.11-main 1.12.2-r2 Natanael Copa <ncopa@alpinelinux.org> fixed
subversion 3.10-main 1.12.2-r1 Natanael Copa <ncopa@alpinelinux.org> fixed