CVE-2020-17525
Summary
| CVE | CVE-2020-17525 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-17 10:15:00 UTC |
| Updated | 2022-01-01 18:03:00 UTC |
| Description | Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn servers 1.10.7 |
Risk And Classification
Problem Types: CWE-476
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Subversion | All | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] [DLA 2646-1] subversion security update | MLIST | lists.debian.org | |
| subversion.apache.org/security/CVE-2020-17525-advisory.txt | MISC | subversion.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Thomas Åkesson (simonsoft.se)
Legacy QID Mappings
- 178601 Debian Security Update for sub (DLA 2646-1)
- 198804 Ubuntu Security Notification for Subversion Vulnerabilities (USN-5445-1)
- 296067 Oracle Solaris 11.4 Support Repository Update (SRU) 33.94.0 Missing (CPUAPR2021)
- 377150 Alibaba Cloud Linux Security Update for subversion:1.10 (ALINUX3-SA-2021:0018)
- 500672 Alpine Linux Security Update for subversion
- 501501 Alpine Linux Security Update for subversion
- 504445 Alpine Linux Security Update for subversion
- 670334 EulerOS Security Update for subversion (EulerOS-SA-2021-1890)
- 670366 EulerOS Security Update for subversion (EulerOS-SA-2021-1959)
- 670387 EulerOS Security Update for subversion (EulerOS-SA-2021-1938)
- 690407 Free Berkeley Software Distribution (FreeBSD) Security Update for mod_dav_svn (06a5abd4-6bc2-11eb-b292-90e2baa3bafc)
- 750362 OpenSUSE Security Update for subversion (openSUSE-SU-2021:0280-1)
- 900112 CBL-Mariner Linux Security Update for subversion 1.14.0
- 901018 Common Base Linux Mariner (CBL-Mariner) Security Update for subversion (6899-1)
- 902999 Common Base Linux Mariner (CBL-Mariner) Security Update for subversion (3983)
- 940067 AlmaLinux Security Update for subversion:1.10 (ALSA-2021:0507)
- 960822 Rocky Linux Security Update for subversion:1.10 (RLSA-2021:0507)