Vulnerability CVE-2022-24070


Published: 2022-04-12

Description:
Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do not use mod_dav_svn are not affected.

Type:

CWE-416

(Use After Free)

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Debian -> Debian linux 
Apache -> Subversion 

 References:
https://bz.apache.org/bugzilla/show_bug.cgi?id=65861
https://issues.apache.org/jira/browse/SVN-4880
https://cwiki.apache.org/confluence/display/HTTPD/ModuleLife
https://www.debian.org/security/2022/dsa-5119

Copyright 2024, cxsecurity.com

 

Back to Top