CVE Vulnerabilities

CVE-2004-0413

Published: Aug 06, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allows remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via an integer overflow that leads to a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Openpkg Openpkg * *
Openpkg Openpkg 2.0 (including) 2.0 (including)
Subversion Subversion 1.0 (including) 1.0 (including)
Subversion Subversion 1.0.1 (including) 1.0.1 (including)
Subversion Subversion 1.0.2 (including) 1.0.2 (including)
Subversion Subversion 1.0.3 (including) 1.0.3 (including)
Subversion Subversion 1.0.4 (including) 1.0.4 (including)

References