Rewterz Threat Advisory -CVE-2018-11803 – Apache Subversion Denial of Service Vulnerability

Friday, February 8, 2019





Analysis Summary

Subversion’s mod_dav_svn Apache HTTPD module will crash after de-referencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation. This issue can be triggered by any client on Subversion repositories configured for anonymous read access. If read access requires authentication, a denial of service attack can only be performed by an authenticated user.


Denial of Service

Affected Products

Apache Subversion 1.11.0

Apache Subversion 1.10.3

Apache Subversion 1.10


Vendor has released updates for the affected products. Update to these versions.

Apache Subversion 1.10.4

Apache Subversion 1.11.1.

Data Sheets

Corporate Brochure

Our Story



Managed Security

Upcoming Rewterz Trainings/Events

Rewterz News

  • 6, March 2019 Rewterz Threat Alert – Threat Indicators – Ursnif/Gozi Malspam
  • 6, March 2019 Rewterz Threat Alert – Threat Actors Targeting Banks Using Tools to Bypass Cyber Security Controls
  • 5, March 2019 Rewterz Threat Alert “Beyond The Grave” Virus – Threat Indicators
  • 5, March 2019 Rewterz Threat Alert – Redaman/RTM Banking Trojan Campaigns

Copyright © Rewterz. All rights reserved.