Vulnerability Description
Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Subversion | <= 1.6.14 |
Related Weaknesses (CWE)
References
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053230.ht
- http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html
- http://mail-archives.apache.org/mod_mbox/subversion-users/201011.mbox/%3C4CD33B6
- http://mail-archives.apache.org/mod_mbox/www-announce/201011.mbox/%3CAANLkTi=5+N
- http://openwall.com/lists/oss-security/2011/01/02/1
- http://openwall.com/lists/oss-security/2011/01/04/10
- http://openwall.com/lists/oss-security/2011/01/04/8
- http://openwall.com/lists/oss-security/2011/01/05/4
- http://secunia.com/advisories/42780Vendor Advisory
- http://secunia.com/advisories/42969
- http://secunia.com/advisories/43115
- http://secunia.com/advisories/43139
- http://secunia.com/advisories/43346
- http://svn.apache.org/repos/asf/subversion/tags/1.6.15/CHANGES
- http://svn.apache.org/viewvc?view=revision&revision=1032808
FAQ
What is CVE-2010-4644?
CVE-2010-4644 is a vulnerability with a CVSS score of 3.5 (LOW). Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blam...
How severe is CVE-2010-4644?
CVE-2010-4644 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-4644?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Subversion.