CVE-2004-0397: Buffer Overflow
Published May 28, 2004
·Updated
Stack-based buffer overflow during the aprtimet data conversion in Subversion 1.0.2 and earlier allows remote attackers to execute arbitrary code via a (1) DAV2 REPORT query or (2) get-dated-rev svn-protocol command.
Affected Software
3 affected components
Subversion Subversion=1.0.2
Subversion Subversion=1.0.1
Subversion Subversion=1.0
Remediation
Patch Available
Patch Available
Event History
May 28, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0397?
CVE-2004-0397 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2004-0397?
To fix CVE-2004-0397, upgrade Subversion to version 1.0.3 or later.
3
What are the affected software versions for CVE-2004-0397?
CVE-2004-0397 affects Subversion versions 1.0.0, 1.0.1, and 1.0.2.
4
What type of attacks exploit CVE-2004-0397?
CVE-2004-0397 can be exploited via DAV2 REPORT queries or by using the get-dated-rev command in svn-protocol.
5
Who is affected by CVE-2004-0397?
Users of Subversion versions 1.0.0 through 1.0.2 are at risk for CVE-2004-0397.