CVE-2013-7393 — Link Following in Apache Subversion
Severity
2.4LOWNVD
EPSS
0.2%
top 61.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 28
Latest updateMay 17
Description
The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to gain privileges via a symlink attack on the pid file created for (1) svnwcsub.py or (2) irkerbridge.py when the --pidfile option is used. NOTE: this issue was SPLIT from CVE-2013-4262 based on different affected versions (ADT3).
CVSS vector
AV:L/AC:H/C:N/I:P/A:PExploitability: 1.5 | Impact: 4.9