CVE-2010-4539
EPSS 1.4%
Description
The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.15, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger the walking of SVNParentPath collections.
How to fix CVE-2010-4539
To remediate CVE-2010-4539, upgrade the affected package to a fixed version below.
- Debian/subversion—upgrade to 1.6.12dfsg-4 or later
Is CVE-2010-4539 being exploited?
Low — EPSS is 1.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.6.12dfsg-4