Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.
The product accesses or uses a pointer that has not been initialized.
Link | Tags |
---|---|
https://usn.ubuntu.com/3869-1/ | third party advisory vendor advisory |
https://lists.apache.org/thread.html/fa71074862373c142d264534385f8ea5d8d6b80d27f36f3c46f55003%40%3Cdev.subversion.apache.org%3E | |
http://www.securityfocus.com/bid/106770 | vdb entry third party advisory broken link |
https://security.gentoo.org/glsa/201904-08 | third party advisory vendor advisory |