[3.8] subversion: malicious SVN clients can crash mod_dav_svn (CVE-2018-11803)
Subversion 1.10.0 introduced server-side support for recursive directory listing operations. The implementation in mod_dav_svn failed to validate the root path of the directory listing provided by the client. If the client omits the root path, mod_dav_svn will deference an uninitialized pointer variable and crash the HTTPD worker process handling the request.
Fixed In Version:
subversion 1.10.4, subversion 1.11.1
(from redmine: issue id 9932, created on 2019-01-28, closed on 2019-01-28)
main/subversion: security upgrade to 1.10.4 fixes #9932