CVE-2013-4262
published 2014-07-28CVE-2013-4262: svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the --pidfile option and running in foreground mode, allows local users to gain privileges via a…
PriorityP47low2.4CVSS 2.0
AVLACHAuSCNIPAP
EPSS
0.61%
45.7th percentile
svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the --pidfile option and running in foreground mode, allows local users to gain privileges via a symlink attack on the pid file. NOTE: this issue was SPLIT due to different affected versions (ADT3). The irkerbridge.py issue is covered by CVE-2013-7393.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | — | — |
| apache | subversion | >= 0 < 1.8.5-1 | 1.8.5-1 |
| apache | subversion | >= 0 < 1.8.5-1 | 1.8.5-1 |
| apache | subversion | >= 0 < 1.8.5-1 | 1.8.5-1 |
| apache | subversion | >= 0 < 1.8.5-1 | 1.8.5-1 |
| debian | subversion | < subversion 1.8.5-1 (bookworm) | subversion 1.8.5-1 (bookworm) |
CVSS provenance
nvdv2.02.4LOWAV:L/AC:H/Au:S/C:N/I:P/A:P
osv2.4LOW
vendor_apache2.4LOW
vendor_debian2.4LOW
vendor_redhat2.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hc4r-gj92-39g7: svnwcsub
ghsa_unreviewed·2022-05-17·CVSS 2.4
CVE-2013-4262 [LOW] CWE-59 GHSA-hc4r-gj92-39g7: svnwcsub
svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the --pidfile option and running in foreground mode, allows local users to gain privileges via a symlink attack on the pid file. NOTE: this issue was SPLIT due to different affected versions (ADT3). The irkerbridge.py issue is covered by CVE-2013-7393.
GHSA
GHSA-vgr5-m78w-8rc3: The daemonize
ghsa_unreviewed·2022-05-17·CVSS 2.4
CVE-2013-7393 [LOW] CWE-59 GHSA-vgr5-m78w-8rc3: The daemonize
The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to gain privileges via a symlink attack on the pid file created for (1) svnwcsub.py or (2) irkerbridge.py when the --pidfile option is used. NOTE: this issue was SPLIT from CVE-2013-4262 based on different affected versions (ADT3).
OSV
CVE-2013-7393: The daemonize
osv·2014-07-28·CVSS 2.4
CVE-2013-7393 [LOW] CVE-2013-7393: The daemonize
The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to gain privileges via a symlink attack on the pid file created for (1) svnwcsub.py or (2) irkerbridge.py when the --pidfile option is used. NOTE: this issue was SPLIT from CVE-2013-4262 based on different affected versions (ADT3).
OSV
CVE-2013-4262: svnwcsub
osv·2014-07-28·CVSS 2.4
CVE-2013-4262 [LOW] CVE-2013-4262: svnwcsub
svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the --pidfile option and running in foreground mode, allows local users to gain privileges via a symlink attack on the pid file. NOTE: this issue was SPLIT due to different affected versions (ADT3). The irkerbridge.py issue is covered by CVE-2013-7393.
Red Hat
subversion: svnwcsub.py and irkerbridge.py are vulnerable to symlink attack
vendor_redhat·2013-08-30·CVSS 2.4
CVE-2013-7393 [LOW] subversion: svnwcsub.py and irkerbridge.py are vulnerable to symlink attack
subversion: svnwcsub.py and irkerbridge.py are vulnerable to symlink attack
The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to gain privileges via a symlink attack on the pid file created for (1) svnwcsub.py or (2) irkerbridge.py when the --pidfile option is used. NOTE: this issue was SPLIT from CVE-2013-4262 based on different affected versions (ADT3).
Statement: Not vulnerable. This issue did not affect the versions of subversion as shipped with Red Hat Enterprise Linux 5 or 6, as they did not ship the vulnerable versions of subversion.
Package: subversion (Red Hat Enterprise Linux 5) - Not affected
Package: subversion (Red Hat Enterprise Linux 6) - Not affected
Package: subversion (Red Hat Enterprise Linux 7) - Not affected
Red Hat
subversion: svnwcsub.py and irkerbridge.py are vulnerable to symlink attack
vendor_redhat·2013-08-30·CVSS 2.4
CVE-2013-4262 [LOW] subversion: svnwcsub.py and irkerbridge.py are vulnerable to symlink attack
subversion: svnwcsub.py and irkerbridge.py are vulnerable to symlink attack
svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the --pidfile option and running in foreground mode, allows local users to gain privileges via a symlink attack on the pid file. NOTE: this issue was SPLIT due to different affected versions (ADT3). The irkerbridge.py issue is covered by CVE-2013-7393.
Statement: Not vulnerable. This issue did not affect the versions of subversion as shipped with Red Hat Enterprise Linux 5 or 6, as they did not ship the vulnerable versions of subversion.
Package: subversion (Red Hat Enterprise Linux 5) - Not affected
Package: subversion (Red Hat Enterprise Linux 6) - Not affected
Package: subversion (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-4262: subversion - svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the --pidfile option an...
vendor_debian·2013·CVSS 2.4
CVE-2013-4262 [LOW] CVE-2013-4262: subversion - svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the --pidfile option an...
svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the --pidfile option and running in foreground mode, allows local users to gain privileges via a symlink attack on the pid file. NOTE: this issue was SPLIT due to different affected versions (ADT3). The irkerbridge.py issue is covered by CVE-2013-7393.
Scope: local
bookworm: resolved (fixed in 1.8.5-1)
bullseye: resolved (fixed in 1.8.5-1)
forky: resolved (fixed in 1.8.5-1)
sid: resolved (fixed in 1.8.5-1)
trixie: resolved (fixed in 1.8.5-1)
Debian
CVE-2013-7393: subversion - The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to g...
vendor_debian·2013·CVSS 2.4
CVE-2013-7393 [LOW] CVE-2013-7393: subversion - The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to g...
The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to gain privileges via a symlink attack on the pid file created for (1) svnwcsub.py or (2) irkerbridge.py when the --pidfile option is used. NOTE: this issue was SPLIT from CVE-2013-4262 based on different affected versions (ADT3).
Scope: local
bookworm: resolved (fixed in 1.8.5-1)
bullseye: resolved (fixed in 1.8.5-1)
forky: resolved (fixed in 1.8.5-1)
sid: resolved (fixed in 1.8.5-1)
trixie: resolved (fixed in 1.8.5-1)
Apache
Apache subversion: CVE-2013-4262
vendor_apache·CVSS 2.4
CVE-2013-4262 [LOW] Apache subversion: CVE-2013-4262
Apache subversion: CVE-2013-4262
-advisory.txt 1.8.0 - 1.8.2 admin-side tools: symlink attack against pid file
No detection rules found.
No public exploits indexed.
2014-07-28
Published