Apache Subversion mod_dav_svn is vulnerable to memory corruption
Published Apr 12, 2022
7.5
HIGHCVSS 3.1
EPSS 9.47%
Description
Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do not use mod_dav_svn are not affected.
Affected products
-
- Version 1.10.0 to 1.14.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Subversion | n/a |
|
Configuration 1
- ≥ 1.10.0 · < 1.10.8
- ≥ 1.14.0 · < 1.14.2
Configuration 2
- 10.0
- 11.0
Configuration 3
- 35
- 36
No data.
Red Hat Enterprise Linux 8
subversion:1.10-8060020210901110943.68c8ceab
Fixed · RHSA-2022:2234
Red Hat Enterprise Linux 8
subversion:1.14-8060020210901110959.06c90725
Fixed · RHSA-2022:4941
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
subversion:1.10-8010020220506111511.fa3af259
Fixed · RHSA-2022:2237
Red Hat Enterprise Linux 8.2 Extended Update Support
subversion:1.10-8020020220506110653.f2093e77
Fixed · RHSA-2022:2236
Red Hat Enterprise Linux 8.4 Extended Update Support
subversion:1.10-8040020201106082712.e8604fa1
Fixed · RHSA-2022:2222
Red Hat Enterprise Linux 8.4 Extended Update Support
subversion:1.14-8040020210210122209.491a7707
Fixed · RHSA-2022:4722
Red Hat Enterprise Linux 9
subversion-0:1.14.1-5.el9_0
Fixed · RHSA-2022:4591
Red Hat Enterprise Linux 6
subversion
Not affected
Red Hat Enterprise Linux 7
subversion
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | subversion:1.10-8060020210901110943.68c8ceab | Fixed | RHSA-2022:2234 |
| Red Hat Enterprise Linux 8 | subversion:1.14-8060020210901110959.06c90725 | Fixed | RHSA-2022:4941 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | subversion:1.10-8010020220506111511.fa3af259 | Fixed | RHSA-2022:2237 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | subversion:1.10-8020020220506110653.f2093e77 | Fixed | RHSA-2022:2236 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | subversion:1.10-8040020201106082712.e8604fa1 | Fixed | RHSA-2022:2222 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | subversion:1.14-8040020210210122209.491a7707 | Fixed | RHSA-2022:4722 |
| Red Hat Enterprise Linux 9 | subversion-0:1.14.1-5.el9_0 | Fixed | RHSA-2022:4591 |
| Red Hat Enterprise Linux 6 | subversion | Not affected | n/a |
| Red Hat Enterprise Linux 7 | subversion | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The vulnerable code was introduced in Subversion 1.10 as part of a new implementation of path-based authorization (authz). Red Hat Enterprise Linux 6 and 7 are not affected by this flaw as they ship an older version of Subversion.
Red Hat mitigation
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
References (14)
- http://seclists.org/fulldisclosure/2022/Jul/18 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2022-24070 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2074772 Issue Tracking
- https://bz.apache.org/bugzilla/show_bug.cgi?id=65861 x_refsource_MISCIssue TrackingVendor Advisory
- https://cwiki.apache.org/confluence/display/HTTPD/ModuleLife x_refsource_MISCVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-28983 Advisory
- https://issues.apache.org/jira/browse/SVN-4880 x_refsource_MISCIssue TrackingVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZ4ARNGLMGYBKYDX2B7DRBNMF6EH3A6R/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YJPMCWCGWBN3QWCDVILWQWPC75RR67LT/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2022-24070
- https://subversion.apache.org/security/CVE-2022-24070-advisory.txt
- https://support.apple.com/kb/HT213345 x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-24070
- https://www.debian.org/security/2022/dsa-5119 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.