Improper Input Validation
Affecting subversion package, versions <1.9.5-1+deb9u4
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server.
References
CVSS Score
7.5
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2019-0203
- CWE
- CWE-20
- Snyk ID
- SNYK-DEBIAN9-SUBVERSION-456173
- Disclosed
- 26 Sep, 2019
- Published
- 31 Jul, 2019