CVE-2013-2088
published 2013-07-31CVE-2013-2088: contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands…
PriorityP356high7.1CVSS 2.0
AVNACHAuSCCICAC
EXPLOIT
EPSS
31.47%
98.1th percentile
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | <= 1.6.21 | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.7.5-1 | 1.7.5-1 |
| apache | subversion | >= 0 < 1.7.5-1 | 1.7.5-1 |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:H/Au:S/C:C/I:C/A:C
osv7.1HIGH
vendor_apache7.1HIGH
vendor_debian7.1LOW
vendor_redhat7.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-92h8-fm5h-34jg: contrib/hook-scripts/svn-keyword-check
ghsa_unreviewed·2022-05-14
CVE-2013-2088 [HIGH] CWE-20 GHSA-92h8-fm5h-34jg: contrib/hook-scripts/svn-keyword-check
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.
OSV
CVE-2013-2088: contrib/hook-scripts/svn-keyword-check
osv·2013-07-31·CVSS 7.1
CVE-2013-2088 [HIGH] CVE-2013-2088: contrib/hook-scripts/svn-keyword-check
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.
Red Hat
subversion: Improper sanitization of arguments of certain hook scripts might lead to arbitrary code execution
vendor_redhat·2013-05-31·CVSS 7.1
CVE-2013-2088 [HIGH] subversion: Improper sanitization of arguments of certain hook scripts might lead to arbitrary code execution
subversion: Improper sanitization of arguments of certain hook scripts might lead to arbitrary code execution
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.
Statement: Not Vulnerable. This issue does not affect the version of subversion as shipped with Red Hat Enterprise Linux 5 and 6.
Package: subversion (Red Hat Enterprise Linux 5) - Not affected
Package: subversion (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2013-2088: subversion - contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows rem...
vendor_debian·2013·CVSS 7.1
CVE-2013-2088 [HIGH] CVE-2013-2088: subversion - contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows rem...
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.
Scope: local
bookworm: resolved (fixed in 1.7.5-1)
bullseye: resolved (fixed in 1.7.5-1)
forky: resolved (fixed in 1.7.5-1)
sid: resolved (fixed in 1.7.5-1)
trixie: resolved (fixed in 1.7.5-1)
Apache
Apache subversion: CVE-2013-2088
vendor_apache·CVSS 7.1
CVE-2013-2088 [HIGH] Apache subversion: CVE-2013-2088
Apache subversion: CVE-2013-2088
-advisory.txt 1.2.0-1.6.23 (see advisory) contrib hook-scripts can allow arbitrary code execution
No detection rules found.
Bugzilla
CVE-2013-2088 subversion: Improper sanitization of arguments of certain hook scripts might lead to arbitrary code execution [fedora-all]
bugzilla·2013-06-03·CVSS 7.1
CVE-2013-2088 [HIGH] CVE-2013-2088 subversion: Improper sanitization of arguments of certain hook scripts might lead to arbitrary code execution [fedora-all]
CVE-2013-2088 subversion: Improper sanitization of arguments of certain hook scripts might lead to arbitrary code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bod
Bugzilla
CVE-2013-2088 subversion: Improper sanitization of arguments of certain hook scripts might lead to arbitrary code execution
bugzilla·2013-06-03·CVSS 7.1
CVE-2013-2088 [HIGH] CVE-2013-2088 subversion: Improper sanitization of arguments of certain hook scripts might lead to arbitrary code execution
CVE-2013-2088 subversion: Improper sanitization of arguments of certain hook scripts might lead to arbitrary code execution
A security flaw was found in the way Subversion, a concurrent version control system, sanitized content of arguments passed to 'check-mime-type.pl' and 'svn-keyword-check.pl' hook scripts. A remote, authenticated attacker could provide a specially-crafted filename that if inspected by some of the aforementioned two scripts, would lead to arbitrary code execution with the privileges of the user running Subversion client.
References:
[1] http://subversion.apache.org/security/CVE-2013-2088-advisory.txt
Announcement:
[2] http://mail-archives.apache.org/mod_mbox/subversion-dev/201305.mbox/%3CCADkdwvTxsMFeHgc8bK2V-2PrSrKoBffTi8+xbHA5tocrrewWew@mail.gmail.com%3E
(1.6.23)
http://lists.opensuse.org/opensuse-updates/2013-07/msg00015.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvRK51pQsybfvsAzjxQJrmVpL0fEa1K4WGkUP9Tzz6KFDw%40mail.gmail.com%3Ehttp://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvTxsMFeHgc8bK2V-2PrSrKoBffTi8%2BxbHA5tocrrewWew%40mail.gmail.com%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18772https://subversion.apache.org/security/CVE-2013-2088-advisory.txthttps://www.exploit-db.com/exploits/40507/http://lists.opensuse.org/opensuse-updates/2013-07/msg00015.htmlhttp://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvRK51pQsybfvsAzjxQJrmVpL0fEa1K4WGkUP9Tzz6KFDw%40mail.gmail.com%3Ehttp://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvTxsMFeHgc8bK2V-2PrSrKoBffTi8%2BxbHA5tocrrewWew%40mail.gmail.com%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18772https://subversion.apache.org/security/CVE-2013-2088-advisory.txthttps://www.exploit-db.com/exploits/40507/
2013-07-31
Published