RULE(RULE ID:321624)

Rule General Information
Release Date: 2019-02-19
Rule Name: Apache Subversion mod_dav_svn Denial of Service Vulnerability (CVE-2018-11803)
Severity:
CVE ID:
Rule Protection Details
Description: Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:106770
https://lists.apache.org/thread.html/fa71074862373c142d264534385f8ea5d8d6b80d27f36f3c46f55003@%3Cdev.subversion.apache.org%3E
https://usn.ubuntu.com/3869-1/
Solutions
Refer to the announcement or patch by the vendor: https://subversion.apache.org/security/CVE-2018-11803-advisory.txt