VID |
50431 |
Severity |
40 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
Apache Subversion clients installed on the remote host prior to version 1.14.4 are affected by a vulnerability due to improper handling of command-line arguments.
- svn is vulnerable to command injection due to improper handling of command-line arguments. A maliciously crafted command-line argument could be misinterpreted, leading to the injection of unintended arguments or even the execution of arbitrary commands. This condition may be mitigated by carefully sanitizing command-line arguments passed to the svn command.(CVE-2024-45720)
* References: https://subversion.apache.org/security/CVE-2024-45720-advisory.txt
* Platforms Affected: Subversion prior to 1.14.4 Any operating system Any version |
Recommendation |
Upgrade to the latest version of Subversion (1.14.4 or later), available from the Subversion Web page at https://subversion.apache.org/download/ |
Related URL |
CVE-2024-45720 (CVE) |
Related URL |
35983 (SecurityFocus) |
Related URL |
(ISS) |
|