Apache Subversion < 1.8.0 / 1.7.10 / 1.6.23 Multiple Vulnerabilities

medium Log Correlation Engine Plugin ID 800980


The remote host is running a version of Apache Subversion that is vulnerable to multiple attack vectors. Subversion is an open-source version-control application that is available for numerous platforms, including Microsoft Windows, UNIX, and UNIX-like operating systems.


The installed version of SVN is affected by the following vulnerabilities:

- Remote denial-of-service vulnerabilities exist due to an error in the svnserve server, as it does not properly handle aborted connection messages. (CVE-2013-1968, CVE-2013-2112)

- A command-injection vulnerability exists in the 'svn-keyword-check.pl' hook script while processing filenames. (CVE-2013-2088)


Updates are available. Alternatively, upgrade to versions 1.8.0, 1.7.10, or 1.6.23.

See Also




Plugin Details

Severity: Medium

ID: 800980

Family: Web Servers

Published: 6/4/2013

Updated: 6/4/2013

Risk Information


Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

Patch Publication Date: 6/3/2013

Vulnerability Publication Date: 6/3/2013

Reference Information

CVE: CVE-2013-1968, CVE-2013-2112, CVE-2013-2088

BID: 60264, 60267, 60265