Summary
The host is running Apache Subversion and is prone to multiple denial of service vulnerabilities.
Impact
Successful exploitation will let the remote attackers to cause a segfault.
Impact Level: Application
NOTE : Configurations which allow anonymous read access to the repository will be vulnerable.
Solution
Upgrade to Apache Subversion version 1.6.21 or 1.7.9 or later, For updates refer to http://subversion.apache.org
Insight
An error within the 'mod_dav_svn' module when handling - 'LOCK' requests against a URL for a non-existent path or invalid activity URL that supports anonymous locks.
- 'PROPFIND' request on an activity URL.
Affected
Apache Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8
References
Severity
Classification
-
CVE CVE-2013-1847, CVE-2013-1849 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities