CVE Vulnerabilities

CVE-2004-0413

Published: Aug 06, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allows remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via an integer overflow that leads to a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Openpkg Openpkg * *
Openpkg Openpkg 2.0 (including) 2.0 (including)
Subversion Subversion 1.0 (including) 1.0 (including)
Subversion Subversion 1.0.1 (including) 1.0.1 (including)
Subversion Subversion 1.0.2 (including) 1.0.2 (including)
Subversion Subversion 1.0.3 (including) 1.0.3 (including)
Subversion Subversion 1.0.4 (including) 1.0.4 (including)
Subversion Ubuntu dapper *
Subversion Ubuntu devel *
Subversion Ubuntu edgy *
Subversion Ubuntu feisty *

References