← Vulnerability feed

Vulnerability record · CVE-2013-1847 · published 2 May 2013

CVE-2013-1847: Subversion mod_dav_svn NULL pointer dereference via anonymous LOCK

Apache · Subversion

The mod_dav_svn Apache HTTPD module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 dereferences a NULL pointer when handling an anonymous LOCK request for a URL that does not exist. A remote unauthenticated attacker can crash the server process, causing a denial of service on the Subversion HTTP service.

5.0 CVSS 2.0 Medium EPSS 51% · top 1.1%
5.0CVSS 2.0 base score
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an anonymous LOCK for a URL that does not exist.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

medium priorityThe flaw is remotely reachable without authentication and has very high EPSS, but it only causes a denial of service with no confidentiality or integrity impact.

What it is

The mod_dav_svn Apache HTTPD module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 dereferences a NULL pointer when handling an anonymous LOCK request for a URL that does not exist. A remote unauthenticated attacker can crash the server process, causing a denial of service on the Subversion HTTP service.

Impact

An attacker gains no data access or code execution; the effect is a server crash that disrupts availability of the Subversion repository service for other users.

Attack surface

Reached over the network through the Apache HTTPD server hosting mod_dav_svn; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required, and the description states the LOCK is anonymous, so no user interaction is needed.

Exploitation

Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is 0.51442 (98.9th percentile), indicating a high modeled likelihood of exploitation activity.

What to do

  • Upgrade Subversion to a release later than 1.6.20 or 1.7.8, or apply the vendor patch referenced in the Apache Subversion security advisory for CVE-2013-1847.
  • Apply the distribution errata for affected packages (Red Hat RHSA-2013-0737, Ubuntu USN-1893-1, openSUSE and Mandriva advisories).
  • If patching is delayed, restrict or disable anonymous LOCK access to mod_dav_svn repositories via Apache authorization configuration.
  • Monitor and rate-limit LOCK requests to nonexistent repository paths at the reverse proxy or web server layer.

Detection

  • Inspect Apache access logs for LOCK requests returning 500 errors or targeting paths that do not exist in the repository.
  • Alert on repeated anonymous LOCK requests from a single source IP within a short window.
  • Monitor for Apache child process crashes or restarts correlated with LOCK method traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-updates/2013-04/msg00095.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00069.html
http://mail-archives.apache.org/mod_mbox/subversion-announce/201304.mbox/%3CCADkdwvRoyVrZV12tgC0FMGrc6%2BMisd3qTcZ%2BDdp
http://mail-archives.apache.org/mod_mbox/subversion-announce/201304.mbox/%3CCADkdwvSTMLbn4q_KM3Ph2UOeSiPGhEK4%3DSvwEjaHW
http://rhn.redhat.com/errata/RHSA-2013-0737.html
http://subversion.apache.org/security/CVE-2013-1847-advisory.txt Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2013:153
http://www.ubuntu.com/usn/USN-1893-1
https://bugzilla.redhat.com/show_bug.cgi?id=929090
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18538
http://lists.opensuse.org/opensuse-updates/2013-04/msg00095.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00069.html
http://mail-archives.apache.org/mod_mbox/subversion-announce/201304.mbox/%3CCADkdwvRoyVrZV12tgC0FMGrc6%2BMisd3qTcZ%2BDdp
http://mail-archives.apache.org/mod_mbox/subversion-announce/201304.mbox/%3CCADkdwvSTMLbn4q_KM3Ph2UOeSiPGhEK4%3DSvwEjaHW
http://rhn.redhat.com/errata/RHSA-2013-0737.html
http://subversion.apache.org/security/CVE-2013-1847-advisory.txt Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2013:153
http://www.ubuntu.com/usn/USN-1893-1
https://bugzilla.redhat.com/show_bug.cgi?id=929090
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18538

Track CVE-2013-1847 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-9800Apache subversion improper input validation vulnerabilityA maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run …EPSS 19%8.8CVE-2013-4246Apache subversion improper access control vulnerabilitylibsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories a…EPSS 2.8%8.6CVE-2015-5259Apache Subversion svn:// protocol integer overflow enables remote code executionApache Subversion 1.9.x before 1.9.3 has an integer overflow in the read_string function in libsvn_ra_svn/marshal.c. A crafted svn:// protocol string…EPSS 57%analysed7.8CVE-2024-45720Apache subversion os command injection vulnerabilityOn Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead…EPSS 0.61%7.8CVE-2015-0202Apache subversion vulnerabilityThe mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large numbe…EPSS 8.0%7.8CVE-2013-2112Apache subversion vulnerabilityThe svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a con…EPSS 3.9%7.6CVE-2015-5343Apache subversion memory buffer overflow vulnerabilityInteger overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users t…EPSS 30%7.5CVE-2022-24070Apache subversion use after free vulnerabilitySubversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use …EPSS 9.5%

Source: NIST National Vulnerability Database (record CVE-2013-1847), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.