CVE-2013-4558
EPSS 5.9%
描述
The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request, as demonstrated using a trailing /.
如何修補 CVE-2013-4558
要修補 CVE-2013-4558,請將受影響套件升級到下列已修補版本。
- Debian/subversion—升級至 1.7.14-1 或更新版本
CVE-2013-4558 正在被利用嗎?
中等 — EPSS 為 5.9%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 1.7.14-1