CVE-2004-0413

Publication date 6 August 2004

Last updated 24 July 2024


Ubuntu priority

libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allows remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via an integer overflow that leads to a heap-based buffer overflow.

Status

Package Ubuntu Release Status
subversion 7.04 feisty
Fixed 1.3.1-3ubuntu1
6.10 edgy
Fixed 1.3.1-3ubuntu1
6.06 LTS dapper
Fixed 1.3.1-3ubuntu1