CVE-2011-1752

High PUBLISHED

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of...

Apache · Subversion

Not yet in CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
5.0 Medium

At a Glance

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.

apache
CVE Published
Jun 06, 2011
Exploitation Reported
Jun 06, 2011
CVSS
5.0 Medium
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • DSA-2251 debian.org · Vendor Advisory http://www.debian.org/security/2011/dsa-2251
  • USN-1144-1 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-1144-1
  • MDVSA-2011:106 mandriva.com · Vendor Advisory http://www.mandriva.com/security/advisories?name=MDVSA-2011:106
  • RHSA-2011:0862 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2011-0862.html
  • FEDORA-2011-8341 lists.fedoraproject.org · Vendor Advisory http://lists.fedoraproject.org/pipermail/package-announce/2011-July/0...
Show 16 more references
  • APPLE-SA-2012-02-01-1 lists.apple.com · Vendor Advisory http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html
  • FEDORA-2011-8352 lists.fedoraproject.org · Vendor Advisory http://lists.fedoraproject.org/pipermail/package-announce/2011-June/0...
  • RHSA-2011:0861 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2011-0861.html
  • 44849 secunia.com · Third-Party Advisory http://secunia.com/advisories/44849
  • 44888 secunia.com · Third-Party Advisory http://secunia.com/advisories/44888
  • 45162 secunia.com · Third-Party Advisory http://secunia.com/advisories/45162
  • 44681 secunia.com · Third-Party Advisory http://secunia.com/advisories/44681
  • 44879 secunia.com · Third-Party Advisory http://secunia.com/advisories/44879
  • 44633 secunia.com · Third-Party Advisory http://secunia.com/advisories/44633
  • 48091 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/48091
  • oval:org.mitre.oval:def:18922 oval.cisecurity.org · VDB Entry https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.m...
  • 1025617 securitytracker.com · VDB Entry http://www.securitytracker.com/id?1025617
  • support.apple.com/kb/HT5130 support.apple.com · CVE Record http://support.apple.com/kb/HT5130
  • subversion.apache.org/security/CVE-2011-1752-advisory.txt subversion.apache.org · CVE Record http://subversion.apache.org/security/CVE-2011-1752-advisory.txt
  • bugzilla.redhat.com/show_bug.cgi bugzilla.redhat.com · CVE Record https://bugzilla.redhat.com/show_bug.cgi?id=709111
  • svn.apache.org/repos/asf/subversion/tags/1.6.17/CHANGES svn.apache.org · CVE Record http://svn.apache.org/repos/asf/subversion/tags/1.6.17/CHANGES

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.