#VU50623 NULL pointer dereference in Subversion - CVE-2020-17525
Published: February 11, 2021
Subversion
Apache Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference when the Subversion is configured to use in-repository authz rules with the AuthzSVNReposRelativeAccessFile option. A remote non-authenticated attacker can send specially crafted request to a non-existing URL, trigger a NULL pointer dereference in the mod_authz_svn module and perform a denial of service (DoS) attack.