HIGH
subversion: Improper sanitization of arguments of certain hook scripts might lead to arbitrary code execution
Published Jul 31, 2013
7.1
HIGHCVSS 2.0
EPSS 31.47%
Description
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.
Affected products
No data.
Configuration 1
OR
- ≤ 1.6.21
- 1.6.0
- 1.6.1
- 1.6.2
- 1.6.3
- 1.6.4
- 1.6.5
- 1.6.6
- 1.6.7
- 1.6.8
- 1.6.9
- 1.6.10
- 1.6.11
- 1.6.12
- 1.6.13
- 1.6.14
- 1.6.15
- 1.6.16
- 1.6.17
- 1.6.18
- 1.6.19
- 1.6.20
- 1.6.17
No data.
Red Hat Enterprise Linux 5
subversion
Not affected
Red Hat Enterprise Linux 6
subversion
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | subversion | Not affected | n/a |
| Red Hat Enterprise Linux 6 | subversion | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Not Vulnerable. This issue does not affect the version of subversion as shipped with Red Hat Enterprise Linux 5 and 6.
Weaknesses (1)
References (10)
- http://lists.opensuse.org/opensuse-updates/2013-07/msg00015.html vendor-advisoryx_refsource_SUSE
- http://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvRK51pQsybfvsAzjxQJrmVpL0fEa1K4WGkUP9Tzz6KFDw%40mail.gmail.com%3E mailing-listx_refsource_MLIST
- http://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvTxsMFeHgc8bK2V-2PrSrKoBffTi8%2BxbHA5tocrrewWew%40mail.gmail.com%3E mailing-listx_refsource_MLIST
- https://access.redhat.com/security/cve/CVE-2013-2088 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=970027 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-2088
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18772 vdb-entrysignaturex_refsource_OVAL
- https://subversion.apache.org/security/CVE-2013-2088-advisory.txt x_refsource_CONFIRMVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2013-2088
- https://www.exploit-db.com/exploits/40507/ exploitx_refsource_EXPLOIT-DB
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-updates/2013-07/msg00015.html | vendor-advisoryx_refsource_SUSE | |
| http://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvRK51pQsybfvsAzjxQJrmVpL0fEa1K4WGkUP9Tzz6KFDw%40mail.gmail.com%3E | mailing-listx_refsource_MLIST | |
| http://mail-archives.apache.org/mod_mbox/subversion-announce/201305.mbox/%3CCADkdwvTxsMFeHgc8bK2V-2PrSrKoBffTi8%2BxbHA5tocrrewWew%40mail.gmail.com%3E | mailing-listx_refsource_MLIST | |
| https://access.redhat.com/security/cve/CVE-2013-2088 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=970027 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-2088 | ||
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18772 | vdb-entrysignaturex_refsource_OVAL | |
| https://subversion.apache.org/security/CVE-2013-2088-advisory.txt | x_refsource_CONFIRMVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2013-2088 | ||
| https://www.exploit-db.com/exploits/40507/ | exploitx_refsource_EXPLOIT-DB |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 31, 2013
Updated Aug 6, 2024
Reserved Feb 19, 2013
Link CVE-2013-2088
CISA Vulnrichment
Updated n/a