{"id":"CVE-2004-0397","details":"Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attackers to execute arbitrary code via a (1) DAV2 REPORT query or (2) get-dated-rev svn-protocol command.","modified":"2026-04-10T03:35:44.113159Z","published":"2004-07-07T04:00:00Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/11642"},{"type":"ADVISORY","url":"http://secunia.com/advisories/11675"},{"type":"ADVISORY","url":"http://security.e-matters.de/advisories/082004.html"},{"type":"ADVISORY","url":"http://subversion.tigris.org/svn-sscanf-advisory.txt"},{"type":"ADVISORY","url":"http://www.linuxsecurity.com/advisories/fedora_advisory-4373.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/archive/1/363814"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/10386"},{"type":"EVIDENCE","url":"http://www.securityfocus.com/bid/10386"},{"type":"FIX","url":"http://www.securityfocus.com/archive/1/363814"},{"type":"FIX","url":"http://www.securityfocus.com/bid/10386"},{"type":"REPORT","url":"https://bugzilla.fedora.us/show_bug.cgi?id=1748"},{"type":"WEB","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021737.html"},{"type":"WEB","url":"http://marc.info/?l=bugtraq&m=108498676517697&w=2"},{"type":"WEB","url":"http://www.gentoo.org/security/en/glsa/glsa-200405-14.xml"},{"type":"WEB","url":"http://www.osvdb.org/6301"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16191"}],"schema_version":"1.7.5"}