CVE-2013-1847: Null Pointer Dereference

Published Mar 29, 2013
·
Updated

It was found that Subversion's moddavsvn Apache HTTPD server module will crash in some circumstances when a LOCK request is made against a non-existent URL. This can lead to DoS.

The vulnerability can be triggered by doing a LOCK request against a URL for a path that does not exist in the repository or an invalid activity URL where authentication is not required for the LOCK method.

Acknowledgements:

Red Hat would like to thank the Apache Subversion project for reporting this issue. Upstream acknowledges Philip Martin and Ben Reser as the original reporter of this flaw.

Other sources

The moddavsvn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an anonymous LOCK for a URL that does not exist.

MITRE

Affected Software

32 affected componentsFixes available
redhat/Subversion<1.6.21
1.6.21
redhat/Subversion<1.7.9
1.7.9
Apache subversion=1.6.0
Apache subversion=1.6.1
Apache subversion=1.6.2
Apache subversion=1.6.3
Apache subversion=1.6.4
Apache subversion=1.6.5
Apache subversion=1.6.6
Apache subversion=1.6.7
Apache subversion=1.6.8
Apache subversion=1.6.9
Apache subversion=1.6.10
Apache subversion=1.6.11
Apache subversion=1.6.12
Apache subversion=1.6.13
Apache subversion=1.6.14
Apache subversion=1.6.15
Apache subversion=1.6.16
Apache subversion=1.6.17
Apache subversion=1.6.18
Apache subversion=1.6.19
Apache subversion=1.6.20
Apache subversion=1.7.0
Apache subversion=1.7.1
Apache subversion=1.7.2
Apache subversion=1.7.3
Apache subversion=1.7.4
Apache subversion=1.7.5
Apache subversion=1.7.6
Apache subversion=1.7.7
Apache subversion=1.7.8

Event History

Mar 29, 2013
Data Sourced
via Red Hat·08:51 AM
DescriptionSeverityAffected Software
May 2, 2013
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2013-1847?

CVE-2013-1847 is classified as a denial-of-service vulnerability.

2

How does CVE-2013-1847 affect affected software?

CVE-2013-1847 can cause the Subversion mod_dav_svn Apache HTTPD server module to crash when a LOCK request is made against a non-existent URL.

3

How do I fix CVE-2013-1847?

To fix CVE-2013-1847, upgrade to Subversion version 1.6.21 or 1.7.9 or later.

4

What versions are affected by CVE-2013-1847?

CVE-2013-1847 affects Subversion versions before 1.6.21 and 1.7.9.

5

Is there a workaround for CVE-2013-1847?

There is no known effective workaround for CVE-2013-1847, so upgrading is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203