CVE-2018-11782: Input Validation
In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-11782?
CVE-2018-11782 is a vulnerability in Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, where the svnserve server process may exit when a well-formed read-only request produces a particular answer.
What is the severity of CVE-2018-11782?
The severity of CVE-2018-11782 is medium with a CVSS score of 6.5.
Which software versions are affected by CVE-2018-11782?
Apache Subversion versions up to and including 1.9.10, 1.10.4, and 1.12.0 are affected by CVE-2018-11782.
How can CVE-2018-11782 be exploited?
CVE-2018-11782 can be exploited by sending a well-formed read-only request that triggers the vulnerability in the svnserve server process.
Is there a fix available for CVE-2018-11782?
Yes, a fix is available for CVE-2018-11782. Users should update their Apache Subversion to a version that is not affected by the vulnerability.