CVE-2013-4246: High severity subversion vulnerability
Published Oct 30, 2017
·Updated
libsvnfsfs/fsfs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories and cause a denial of service or obtain sensitive information by editing packed revision properties.
Affected Software
5 affected components
Apache subversion=1.8.0
Apache subversion=1.8.0-rc1
Apache subversion=1.8.0-rc2
Apache subversion=1.8.0-rc3
Apache subversion=1.8.1
Remediation
Event History
Oct 30, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this Apache Subversion vulnerability?
The vulnerability ID of this Apache Subversion vulnerability is CVE-2013-4246.
2
What is the severity level of CVE-2013-4246?
The severity level of CVE-2013-4246 is high (8.8).
3
What is the impact of CVE-2013-4246?
CVE-2013-4246 might allow remote authenticated users to corrupt FSFS repositories, causing a denial of service or obtaining sensitive information.
4
Which versions of Apache Subversion are affected by CVE-2013-4246?
Apache Subversion 1.8.0, 1.8.0-rc1, 1.8.0-rc2, and 1.8.0-rc3 are affected by CVE-2013-4246.
5
How can I fix CVE-2013-4246?
To fix CVE-2013-4246, upgrade to Apache Subversion 1.8.2 or a later version.