CVE-2004-0397

Subversion <1.0.2 - RCE

Title source: llm

Description

Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attackers to execute arbitrary code via a (1) DAV2 REPORT query or (2) get-dated-rev svn-protocol command.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubydosunix
https://www.exploit-db.com/exploits/16284
exploitdb WORKING POC VERIFIED
by Gyan Chawdhary · cremotelinux
https://www.exploit-db.com/exploits/304
exploitdb WORKING POC VERIFIED
by spoonm · rubyremotemultiple
https://www.exploit-db.com/exploits/9935
metasploit WORKING POC NORMAL
rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/svn/svnserve_date.rb

Scores

EPSS 0.8659
EPSS Percentile 99.4%

Details

Status published
Products (3)
subversion/subversion 1.0
subversion/subversion 1.0.1
subversion/subversion 1.0.2
Published Jul 07, 2004
Tracked Since Feb 18, 2026