Vulnerability record · CVE-2013-1884 · published 2 May 2013
CVE-2013-1884: Subversion mod_dav_svn crash via invalid log REPORT limit
Apache · Subversion
The mod_dav_svn module in Apache Subversion 1.7.0 through 1.7.8 mishandles a log REPORT request with an invalid limit, accessing an uninitialized variable. This causes a segmentation fault and crashes the Apache HTTPD server process, taking down the affected service.
Description
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variable.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityThe flaw is remotely reachable without authentication and causes a denial of service, but it only crashes the service with no code execution or data compromise, and the affected versions are long outdated.
What it is
The mod_dav_svn module in Apache Subversion 1.7.0 through 1.7.8 mishandles a log REPORT request with an invalid limit, accessing an uninitialized variable. This causes a segmentation fault and crashes the Apache HTTPD server process, taking down the affected service.
Impact
An attacker can crash the Subversion server, causing a denial of service for all users of that HTTPD instance. There is no reported data confidentiality or integrity impact.
Attack surface
Reachable remotely over the network via an HTTP request to the mod_dav_svn endpoint; the CVSS vector indicates no authentication is required and no user interaction is needed.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at 0.50538 (98.86th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade Subversion to a version later than 1.7.8 that contains the fix, or apply the vendor patch referenced in the Apache advisory.
- If immediate upgrade is not possible, restrict network access to mod_dav_svn endpoints to trusted clients only.
- Monitor and rate-limit abnormal REPORT request patterns at the reverse proxy or WAF layer.
- Verify the deployed Subversion version against the affected 1.7.0 through 1.7.8 range and track remediation.
Detection
- Monitor Apache HTTPD error logs for segmentation faults or child process crashes tied to mod_dav_svn.
- Inspect HTTP access logs for REPORT requests to Subversion paths with malformed or unusual limit parameters.
- Alert on repeated server process restarts or availability drops on Subversion hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-1884 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-1884), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.