HIGH
subversion: Remote DoS due improper handling of early-closing TCP connections
Published Jul 31, 2013
7.8
HIGHCVSS 2.0
EPSS 3.89%
Description
The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection.
Affected products
No data.
Configuration 1
OR
- ≤ 1.6.21
- 1.6.0
- 1.6.1
- 1.6.2
- 1.6.3
- 1.6.4
- 1.6.5
- 1.6.6
- 1.6.7
- 1.6.8
- 1.6.9
- 1.6.10
- 1.6.11
- 1.6.12
- 1.6.13
- 1.6.14
- 1.6.15
- 1.6.16
- 1.6.17
- 1.6.18
- 1.6.19
- 1.6.20
- 1.6.17
Configuration 2
OR
- 1.7.0
- 1.7.1
- 1.7.2
- 1.7.3
- 1.7.4
- 1.7.5
- 1.7.6
- 1.7.7
- 1.7.8
- 1.7.9
Configuration 3
OR
- 12.04
- 12.10
- 13.04
- 11.4
No data.
Red Hat Enterprise Linux 5
subversion-0:1.6.11-12.el5_10
Fixed · RHSA-2014:0255
Red Hat Enterprise Linux 6
subversion-0:1.6.11-10.el6_5
Fixed · RHSA-2014:0255
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | subversion-0:1.6.11-12.el5_10 | Fixed | RHSA-2014:0255 |
| Red Hat Enterprise Linux 6 | subversion-0:1.6.11-10.el6_5 | Fixed | RHSA-2014:0255 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the version of subversion as shipped with Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.
Weaknesses (0)
No CWE recorded.
References (12)
- http://lists.opensuse.org/opensuse-updates/2013-07/msg00015.html vendor-advisoryx_refsource_SUSE
- http://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvRK51pQsybfvsAzjxQJrmVpL0fEa1K4WGkUP9Tzz6KFDw%40mail.gmail.com%3E mailing-listx_refsource_MLIST
- http://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvTxsMFeHgc8bK2V-2PrSrKoBffTi8%2BxbHA5tocrrewWew%40mail.gmail.com%3E mailing-listx_refsource_MLIST
- http://rhn.redhat.com/errata/RHSA-2014-0255.html vendor-advisoryx_refsource_REDHAT
- http://www.debian.org/security/2013/dsa-2703 vendor-advisoryx_refsource_DEBIAN
- http://www.ubuntu.com/usn/USN-1893-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2013-2112 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=970037 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-2112
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19057 vdb-entrysignaturex_refsource_OVAL
- https://subversion.apache.org/security/CVE-2013-2112-advisory.txt x_refsource_CONFIRMVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2013-2112
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 31, 2013
Updated Aug 6, 2024
Reserved Feb 19, 2013
Link CVE-2013-2112
CISA Vulnrichment
Updated n/a