CVE-2018-11803: High severity Apache subversion vulnerability
Last updated 25 August 2025
Other sources
Subversion's moddavsvn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-11803?
CVE-2018-11803 is a vulnerability found in Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3.
How severe is CVE-2018-11803?
CVE-2018-11803 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2018-11803?
Subversion versions 1.11.0 and 1.10.0 to 1.10.3 are affected by CVE-2018-11803.
How can I mitigate CVE-2018-11803?
To mitigate CVE-2018-11803, you should update Subversion to version 1.10.4 or higher.
Where can I find more information about CVE-2018-11803?
You can find more information about CVE-2018-11803 at the following references: [reference 1](https://subversion.apache.org/security/CVE-2018-11803-advisory.txt), [reference 2](https://www.openwall.com/lists/oss-security/2019/01/23/1), [reference 3](https://security-tracker.debian.org/tracker/CVE-2018-11803)