Input validation error in Subversion - CVE-2019-0203
Published: July 31, 2019 / Updated: August 7, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error when processing a certain sequence of commands within the svnserve process. A remote non-authenticated attacker can send specially crafted commends to the Subversion server and perform a denial of service (DoS) attack.
Affected software
CENTUM VP
B/M9000 VP
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Opensuse
Ubuntu
Fedora
ProSafe-RS
CENTUM VP Entry Class
subversion (Debian package)
subversion (Alpine package)
subversion (Ubuntu package)
libapache2-mod-svn (Ubuntu package)
libsvn1 (Ubuntu package)
subversion
cflinuxfs3
Isolation Segment
VMware Tanzu Application Service for VMs
How to mitigate CVE-2019-0203
CENTUM VP - update to R6.08.00
ProSafe-RS - update to R4.06.00
CENTUM VP Entry Class - update to R6.08.00
subversion (Debian package) - addressed in versions 1.9.5-1+deb9u4, 1.10.4-1+deb10u1
subversion (Alpine package) - update to 1.9.12-r0
subversion (Ubuntu package) - addressed in versions 1.9.3-2ubuntu1.3, 1.9.7-4ubuntu1.1, 1.13.0-3ubuntu0.2
cflinuxfs3 - update to 0.300.0
libapache2-mod-svn (Ubuntu package) - addressed in versions 1.9.7-4ubuntu1.1, 1.13.0-3ubuntu0.2
libsvn1 (Ubuntu package) - addressed in versions 1.9.7-4ubuntu1.1, 1.13.0-3ubuntu0.2
subversion - update to 1.12.2-1.fc30
Isolation Segment - addressed in versions 2.7.45, 2.10.25, 2.11.14, 2.12.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.50, 2.10.32, 2.11.20, 2.12.15, 2.13.5
External References
Related Security Bulletins
- Remote DoS in Apache Subversion
- Ubuntu update for Subversion
- Debian update for subversion
- OpenSUSE Linux update for subversion
- Red Hat update for subversion:1.10
- Arch Linux update for subversion
- Amazon Linux AMI update for subversion
- Input validation error in subversion (Alpine package)
- Multiple vulnerabilities in Yokogawa CENTUM, ProSafe-RS and B/M9000 VP
- Ubuntu update for subversion
- Multiple vulnerabilities in Cloud Foundry Foundation cflinuxfs3
- VMware Tanzu products update for Subversion
- Fedora 30 update for subversion