CVE-2013-4558

low
Published 2013-12-07 · Modified 2026-04-29
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request, as demonstrated using a trailing /.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-4558

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://subversion.apache.org/security/CVE-2013-4558-advisory.txt

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.7.14-1
debian debianbullseyefixed1.7.14-1
debian debianforkyfixed1.7.14-1
debian debiansidfixed1.7.14-1
debian debiantrixiefixed1.7.14-1

Application impact

VendorProductVersionsFixed
apache apachemod_dav_svn-
apache apachesubversion1.7.11
apache apachesubversion1.7.12
apache apachesubversion1.7.13
apache apachesubversion1.8.1
apache apachesubversion1.8.2
apache apachesubversion1.8.3
apache apachesubversion1.8.4

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.