The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large number of REPORT requests, which trigger the traversal of FSFS repository nodes.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Subversion | Apache | 1.8.0 (including) | 1.8.0 (including) |
| Subversion | Apache | 1.8.1 (including) | 1.8.1 (including) |
| Subversion | Apache | 1.8.2 (including) | 1.8.2 (including) |
| Subversion | Apache | 1.8.3 (including) | 1.8.3 (including) |
| Subversion | Apache | 1.8.4 (including) | 1.8.4 (including) |
| Subversion | Apache | 1.8.5 (including) | 1.8.5 (including) |
| Subversion | Apache | 1.8.6 (including) | 1.8.6 (including) |
| Subversion | Apache | 1.8.7 (including) | 1.8.7 (including) |
| Subversion | Apache | 1.8.8 (including) | 1.8.8 (including) |
| Subversion | Apache | 1.8.9 (including) | 1.8.9 (including) |
| Subversion | Apache | 1.8.10 (including) | 1.8.10 (including) |
| Subversion | Apache | 1.8.11 (including) | 1.8.11 (including) |
| Subversion | Ubuntu | lucid | * |
| Subversion | Ubuntu | trusty | * |
| Subversion | Ubuntu | upstream | * |
| Subversion | Ubuntu | utopic | * |
| Subversion | Ubuntu | vivid | * |