[3.9] subversion: malicious SVN clients can crash mod_dav_svn (CVE-2018-11803)
Subversion 1.10.0 introduced server-side support for recursive directory listing operations. The implementation in mod_dav_svn failed to validate the root path of the directory listing provided by the client. If the client omits the root path, mod_dav_svn will deference an uninitialized pointer variable and crash the HTTPD worker process handling the request.
Fixed In Version:
subversion 1.10.4, subversion 1.11.1
References:
https://subversion.apache.org/security/CVE-2018-11803-advisory.txt
(from redmine: issue id 9931, created on 2019-01-28, closed on 2019-01-28)
- Relations:
- parent #9930 (closed)
- Changesets:
- Revision 7bb81a13 on 2019-01-28T16:15:54Z:
main/subversion: security upgrade to 1.11.1
fixes #9931