NULL pointer dereference in Subversion - CVE-2020-17525
Published: February 11, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference when the Subversion is configured to use in-repository authz rules with the AuthzSVNReposRelativeAccessFile option. A remote non-authenticated attacker can send specially crafted request to a non-existing URL, trigger a NULL pointer dereference in the mod_authz_svn module and perform a denial of service (DoS) attack.
Affected software
Amazon Linux AMI
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Ubuntu
Fedora
subversion (Debian package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
libapache2-svn (Ubuntu package)
libapache2-mod-svn (Ubuntu package)
subversion (Ubuntu package)
libsvn1 (Ubuntu package)
subversion
cflinuxfs3
Isolation Segment
VMware Tanzu Application Service for VMs
How to mitigate CVE-2020-17525
subversion (Debian package) - update to 1.10.4-1+deb10u
libapache2-svn (Ubuntu package) - update to UA Infra or UA Desktop
libapache2-mod-svn (Ubuntu package) - addressed in versions UA Infra or UA Desktop, 1.9.7-4ubuntu1.1, 1.13.0-3ubuntu0.2
subversion (Ubuntu package) - addressed in versions UA Infra or UA Desktop, 1.9.7-4ubuntu1.1, 1.13.0-3ubuntu0.2
libsvn1 (Ubuntu package) - addressed in versions UA Infra or UA Desktop, 1.9.7-4ubuntu1.1, 1.13.0-3ubuntu0.2
cflinuxfs3 - update to 0.300.0
subversion - addressed in versions 1.14.1-1.fc32, 1.14.1-1.fc33
Isolation Segment - addressed in versions 2.7.45, 2.10.25, 2.11.14, 2.12.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.50, 2.10.32, 2.11.20, 2.12.15, 2.13.5
External References
Related Security Bulletins
- Denial of service in Apache Subversion
- Debian update for subversion
- Red Hat Enterprise Linux 8 update for the subversion:1.10 module
- Red Hat Enterprise Linux 8.2 update for the subversion:1.10 module
- Red Hat Enterprise Linux 8.1 update for the subversion:1.10 module
- Amazon Linux AMI update for subversion
- Ubuntu update for subversion
- Ubuntu update for subversion
- Multiple vulnerabilities in Cloud Foundry Foundation cflinuxfs3
- VMware Tanzu products update for Subversion
- Fedora 33 update for subversion
- Fedora 32 update for subversion