CVE-2022-24070

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
12/04/2022
Last modified:
07/11/2023

Description

Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do not use mod_dav_svn are not affected.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:* 1.10.0 (including) 1.10.8 (excluding)
cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:* 1.14.0 (including) 1.14.2 (excluding)
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* 12.0 (including) 12.5 (excluding)