Back

HIGH

Apache Subversion mod_dav_svn is vulnerable to memory corruption

Published Apr 12, 2022

Description

Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do not use mod_dav_svn are not affected.

Affected products

Remediation

Red Hat statement

The vulnerable code was introduced in Subversion 1.10 as part of a new implementation of path-based authorization (authz). Red Hat Enterprise Linux 6 and 7 are not affected by this flaw as they ship an older version of Subversion.

Red Hat mitigation

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Apr 12, 2022
Updated Aug 3, 2024
Reserved Jan 27, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Nov 4, 2021
ENISA EUVD
Assigner apache
Published Apr 12, 2022
Updated Aug 3, 2024
Exploited since n/a
EUVD-2022-28983