The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Subversion | Apache | * | 1.6.17 (excluding) |
Red Hat Enterprise Linux 4 | RedHat | subversion-0:1.1.4-4.el4 | * |
Red Hat Enterprise Linux 5 | RedHat | subversion-0:1.6.11-7.el5_6.4 | * |
Red Hat Enterprise Linux 6 | RedHat | subversion-0:1.6.11-2.el6_1.4 | * |
Subversion | Ubuntu | devel | * |
Subversion | Ubuntu | hardy | * |
Subversion | Ubuntu | lucid | * |
Subversion | Ubuntu | maverick | * |
Subversion | Ubuntu | natty | * |
Subversion | Ubuntu | upstream | * |