APP: Subversion Date Svnserve
This signature detects attempts to exploit a known vulnerability in the Subversion Svnserve. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.
Extended Description
Subversion is prone to a buffer-overflow vulnerability that resides in one of its data-parsing functions. Specifically, Subversion calls an 'sscanf()' function when converting data strings to different formats. As a result, the software copies user-supplied data into an unspecified buffer without proper boundary checks. Subversion 1.0.2 and prior versions are prone to this issue.
Affected Products
Subversion subversion
References
BugTraq: 10386
CVE: CVE-2004-0397
URL: http://lists.netsys.com/pipermail/full-disclosure/2004-May/021737.html
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Subversion
Gentoo
7.5