CVE-2022-24070
12.04.2022, 18:15
Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do not use mod_dav_svn are not affected.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | subversion | 1.10.0 ≤ 𝑥 < 1.10.8 |
| apache | subversion | 1.14.0 ≤ 𝑥 < 1.14.2 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
| apple | macos | 12.0 ≤ 𝑥 < 12.5 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| subversion |
| ||||||||||||||||||||||||||||||||||||||||||
| subversion-bash-completion |
| ||||||||||||||||||||||||||||||||||||||||||
| subversion-devel |
| ||||||||||||||||||||||||||||||||||||||||||
| subversion-perl |
| ||||||||||||||||||||||||||||||||||||||||||
| subversion-python |
| ||||||||||||||||||||||||||||||||||||||||||
| subversion-server |
| ||||||||||||||||||||||||||||||||||||||||||
| subversion-tools |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| mod |
| ||
| python3-subversion |
| ||
| subversion |
| ||
| subversion-devel |
| ||
| subversion-gnome |
| ||
| subversion-libs |
| ||
| subversion-perl |
| ||
| subversion-tools |
|
Common Weakness Enumeration
References