CVE-2018-11803: Apache Subversion
High severity, CVSS 7.5. EPSS: 58.5% chance of exploitation in the next 30 days.
Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.
Affected products
- Apache Subversion: from 1.10.0, up to and including 1.10.3; version 1.11.0 only
- Canonical Ubuntu Linux: version 18.10 only
Published 2019-02-05. Last modified 2026-06-17.