Vulnerability CVE-2020-17525: Information

Description

Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: March 17, 2021
Modified: Jan. 1, 2022
Error type identifier: CWE-476

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
subversionsisyphus1.14.1-alt11.14.3-alt1ALT-PU-2021-1334-1266312Fixed
subversionp101.14.1-alt11.14.1-alt1ALT-PU-2021-1334-1266312Fixed
subversionp91.14.1-alt11.14.1-alt1ALT-PU-2021-1348-1266313Fixed
subversionc10f11.14.1-alt11.14.2-alt1ALT-PU-2021-1334-1266312Fixed
subversionc9f21.14.1-alt11.14.1-alt1ALT-PU-2021-1355-1266314Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:*
      Start including
      1.11.0
      End excliding
      1.14.1

      cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:*
      Start including
      1.9.0
      End excliding
      1.10.7

      Configuration 2

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*