CVE Database
/

CVE-2014-0032

Back to search

CVE-2014-0032

Published: Feb 14, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

The get_resource function in repos.c in the mod_dav_svn module in Apache Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is enabled, allows remote attackers to cause a denial of service (crash) via vectors related to the server root and request methods other than GET, as demonstrated by the "svn ls http://svn.example.com" command.

VendorProductVersions

n/a

n/a

affected
n/a

References

56822
third-party-advisory
x_refsource_SECUNIA
61321
third-party-advisory
x_refsource_SECUNIA
USN-2316-1
vendor-advisory
x_refsource_UBUNTU
102927
vdb-entry
x_refsource_OSVDB
RHSA-2014:0255
vendor-advisory
x_refsource_REDHAT
65434
vdb-entry
x_refsource_BID
openSUSE-SU-2014:0307
vendor-advisory
x_refsource_SUSE
60722
third-party-advisory
x_refsource_SECUNIA
openSUSE-SU-2014:0334
vendor-advisory
x_refsource_SUSE
GLSA-201610-05
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now