The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a crafted header in a (1) MOVE or (2) COPY request, involving an authorization check.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Subversion | Apache | * | 1.8.15 (including) |
Subversion | Apache | 1.9.0 (including) | 1.9.0 (including) |
Subversion | Apache | 1.9.1 (including) | 1.9.1 (including) |
Subversion | Apache | 1.9.2 (including) | 1.9.2 (including) |
Subversion | Apache | 1.9.3 (including) | 1.9.3 (including) |
Subversion | Ubuntu | precise | * |
Subversion | Ubuntu | trusty | * |
Subversion | Ubuntu | upstream | * |
Subversion | Ubuntu | wily | * |
Subversion | Ubuntu | xenial | * |