---
cve: "CVE-2013-1847"
severity: "LOW"
cvss: 3.1
epss: "51.4%"
vendor: "n/a"
kev: false
exploited: false
published: "2013-05-02 14:55:05"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-16T01:14:11+02:00"
---

# CVE-2013-1847

> 3.1 LOW

## Beschreibung

The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an anonymous LOCK for a URL that does not exist.

## Exploit-Evidenz

- [EDB-38421 — Apache Subversion 1.6.x - 'mod_dav_svn/lock.c' Remote Denial of Service](https://www.exploit-db.com/exploits/38421) ✅

## Referenzen

- <http://lists.opensuse.org/opensuse-updates/2013-04/msg00095.html>
- <http://rhn.redhat.com/errata/RHSA-2013-0737.html>
- <https://bugzilla.redhat.com/show_bug.cgi?id=929090>
- <http://mail-archives.apache.org/mod_mbox/subversion-announce/201304.mbox/%3CCADkdwvSTMLbn4q_KM3Ph2UOeSiPGhEK4%3DSvwEjaHW_GUGkYWPQ%40mail.gmail.com%3E>
- <http://subversion.apache.org/security/CVE-2013-1847-advisory.txt>
- <http://mail-archives.apache.org/mod_mbox/subversion-announce/201304.mbox/%3CCADkdwvRoyVrZV12tgC0FMGrc6%2BMisd3qTcZ%2BDdpFGgTahkgAkQ%40mail.gmail.com%3E>
- <http://www.ubuntu.com/usn/USN-1893-1>
- <https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18538>
- <http://lists.opensuse.org/opensuse-updates/2013-06/msg00069.html>
- <http://www.mandriva.com/security/advisories?name=MDVSA-2013:153>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2013-1847) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
