CVE-2013-1884
EPSS 50.5%
描述
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variable.
如何修補 CVE-2013-1884
要修補 CVE-2013-1884,請將受影響套件升級到下列已修補版本。
- Debian/subversion—升級至 1.7.9-1 或更新版本
CVE-2013-1884 正在被利用嗎?
可能 — EPSS 為 50.5%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 1.7.9-1