CVE-2019-0203: Null Pointer Dereference
In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-0203?
CVE-2019-0203 is a vulnerability in Apache Subversion that can cause the svnserve server process to exit when certain sequences of protocol commands are sent by a client.
Which versions of Apache Subversion are affected by CVE-2019-0203?
Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0 are affected by CVE-2019-0203.
What is the severity of CVE-2019-0203?
CVE-2019-0203 has a severity score of 7.5 (high).
How can CVE-2019-0203 be exploited?
CVE-2019-0203 can be exploited by sending certain sequences of protocol commands to the svnserve server process.
Is there a fix available for CVE-2019-0203?
Yes, the fix for CVE-2019-0203 is to upgrade Apache Subversion to version 1.9.11, 1.10.6, or 1.12.2.