subversion: malicious SVN clients can crash mod_dav_svn (CVE-2018-11803)
Subversion 1.10.0 introduced server-side support for recursive directory listing operations. The implementation in mod_dav_svn failed to validate the root path of the directory listing provided by the client. If the client omits the root path, mod_dav_svn will deference an uninitialized pointer variable and crash the HTTPD worker process handling the request.
Fixed In Version:¶
subversion 1.10.4, subversion 1.11.1