CVE-2019-0203

Description

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversions svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
6.638

Associated Vulnerability

VulnerabilityOS Platform
subversion security update(DSA-4490-1) subversion_1.9.5-1+deb9u4_i386.debLinux
subversion security update(DSA-4490-1) subversion_1.9.5-1+deb9u4_amd64.debLinux
subversion security update(DSA-4490-1) subversion_1.10.4-1+deb10u1_amd64.debLinux
(RHSA-2019:2512) subversion:1.10 security update libserf-1.3.9-9.module+el8.0.0+3900+919b6753.x86_64.rpmLinux
(RHSA-2019:2512) subversion:1.10 security update libserf-debugsource-1.3.9-9.module+el8.0.0+3900+919b6753.x86_64.rpmLinux
(RHSA-2019:2512) subversion:1.10 security update mod_dav_svn-1.10.2-2.module+el8.0.0+3900+919b6753.x86_64.rpmLinux
(RHSA-2019:2512) subversion:1.10 security update subversion-1.10.2-2.module+el8.0.0+3900+919b6753.x86_64.rpmLinux
(RHSA-2019:2512) subversion:1.10 security update subversion-debugsource-1.10.2-2.module+el8.0.0+3900+919b6753.x86_64.rpmLinux
(RHSA-2019:2512) subversion:1.10 security update subversion-devel-1.10.2-2.module+el8.0.0+3900+919b6753.x86_64.rpmLinux
(RHSA-2019:2512) subversion:1.10 security update subversion-gnome-1.10.2-2.module+el8.0.0+3900+919b6753.x86_64.rpmLinux
(RHSA-2019:2512) subversion:1.10 security update subversion-javahl-1.10.2-2.module+el8.0.0+3900+919b6753.noarch.rpmLinux
(RHSA-2019:2512) subversion:1.10 security update subversion-libs-1.10.2-2.module+el8.0.0+3900+919b6753.x86_64.rpmLinux
(RHSA-2019:2512) subversion:1.10 security update subversion-perl-1.10.2-2.module+el8.0.0+3900+919b6753.x86_64.rpmLinux
(RHSA-2019:2512) subversion:1.10 security update subversion-tools-1.10.2-2.module+el8.0.0+3900+919b6753.x86_64.rpmLinux
(RHSA-2019:2512) subversion:1.10 security update utf8proc-2.1.1-5.module+el8.0.0+3900+919b6753.x86_64.rpmLinux
(RHSA-2019:2512) subversion:1.10 security update utf8proc-debugsource-2.1.1-5.module+el8.0.0+3900+919b6753.x86_64.rpmLinux
Libserf update (ELSA-2019-2512) libserf-1.3.9-9.module+el8.0.0+5251+b51029f7.x86_64.rpmLinux
Mod_dav_svn update (ELSA-2019-2512) mod_dav_svn-1.10.2-2.module+el8.0.0+5251+b51029f7.x86_64.rpmLinux
Subversion update (ELSA-2019-2512) subversion-1.10.2-2.module+el8.0.0+5251+b51029f7.x86_64.rpmLinux
Subversion-devel update (ELSA-2019-2512) subversion-devel-1.10.2-2.module+el8.0.0+5251+b51029f7.x86_64.rpmLinux
Subversion-gnome update (ELSA-2019-2512) subversion-gnome-1.10.2-2.module+el8.0.0+5251+b51029f7.x86_64.rpmLinux
Subversion-libs update (ELSA-2019-2512) subversion-libs-1.10.2-2.module+el8.0.0+5251+b51029f7.x86_64.rpmLinux
Subversion-perl update (ELSA-2019-2512) subversion-perl-1.10.2-2.module+el8.0.0+5251+b51029f7.x86_64.rpmLinux
Subversion-tools update (ELSA-2019-2512) subversion-tools-1.10.2-2.module+el8.0.0+5251+b51029f7.x86_64.rpmLinux
Utf8proc update (ELSA-2019-2512) utf8proc-2.1.1-5.module+el8.0.0+5251+b51029f7.x86_64.rpmLinux
Subversion-javahl update (ELSA-2019-2512) subversion-javahl-1.10.2-2.module+el8.0.0+5251+b51029f7.noarch.rpmLinux
Advanced version control system (USN-5445-1) libsvn1_1.9.7-4ubuntu1.1_i386.debLinux
Advanced version control system (USN-5445-1) libsvn1_1.9.7-4ubuntu1.1_amd64.debLinux
Advanced version control system (USN-5445-1) libsvn1_1.13.0-3ubuntu0.2_amd64.debLinux
Advanced version control system (USN-5445-1) subversion_1.9.7-4ubuntu1.1_i386.debLinux
Advanced version control system (USN-5445-1) subversion_1.9.7-4ubuntu1.1_amd64.debLinux
Advanced version control system (USN-5445-1) subversion_1.13.0-3ubuntu0.2_amd64.debLinux
Advanced version control system (USN-5445-1) libapache2-mod-svn_1.9.7-4ubuntu1.1_i386.debLinux
Advanced version control system (USN-5445-1) libapache2-mod-svn_1.9.7-4ubuntu1.1_amd64.debLinux
Advanced version control system (USN-5445-1) libapache2-mod-svn_1.13.0-3ubuntu0.2_amd64.debLinux
subversion:1.10 security update (RLSA-2019:2512) libserf-1.3.9-9.module+el8.4.0+407+38733e5a.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234