CVE-2018-11803 identifies a high-severity vulnerability in Subversion's mod_dav_svn Apache HTTPD module, affecting versions 1.11.0 and 1.10.0-1.10.3, including Apache Ubuntu Linux and Canonical Subversion deployments. This flaw allows an unauthenticated, remote attacker to trigger a denial-of-service (crash) by omitting the root path in a recursive directory listing, due to dereferencing an uninitialized pointer. Rated 7.5 (High) on CVSSv3, the attack complexity is low, primarily impacting system availability. Although not in CISA's KEV catalog and lacking public exploit code, it is marked as "Active" on some tracking lists and has generated community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.10.0, <= 1.10.3CPE matchmatch criteria | cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:* | ||
1.11.0CPE matchmatch criteria | cpe:2.3:a:apache:subversion:1.11.0:*:*:*:*:*:*:* | ||
18.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.