A NULL pointer dereference flaw was found in the way mod_dav_svn, Apache httpd module for Subversion server, processed certain requests to display collection of Subversion repositories, available on particular host, when listing of repositories (SVNListParentPath directive) was enabled. A remote user could use this flaw to cause denial of service (particular httpd thread crash). References: [1] http://svn.apache.org/repos/asf/subversion/tags/1.6.15/CHANGES Upstream changeset: [2] http://svn.apache.org/viewvc?view=revision&revision=1033166 Public PoC: [3] http://svn.haxx.se/users/archive-2010-11/0084.shtml Flaw exploitation note: ----------------------- This flaw to be successfully exploited requires the "SVNListParentPath" directive / listing of repositories to be enabled. This feature is turned off by default in versions of subversion package, as shipped with Red Hat Enterprise Linux 5 and 6, which prevents occurrence / exploitation of this flaw.
This issue did NOT affect the version of the subversion package, as shipped with Red Hat Enterprise Linux 4 as it did not include the support for repositories listing (SVNListParentPath directive) yet. This issue affects the versions of the subversion package, as shipped with Red Hat Enterprise Linux 5 and 6. -- This issue affects the version of the subversion package, as shipped with Fedora release of 13. The updated / patched version of subversion package has been already pushed to Fedora-14 -testing repository. Once it undergoes the required testing process, it will be pushed to the -stable repository.
The CVE identifier of CVE-2010-4539 has been assigned to this issue: http://www.openwall.com/lists/oss-security/2011/01/05/4
Created subversion tracking bugs for this issue Affects: fedora-13 [bug 667786]
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2011:0257 https://rhn.redhat.com/errata/RHSA-2011-0257.html
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2011:0258 https://rhn.redhat.com/errata/RHSA-2011-0258.html