Back

LOW

subversion: svnwcsub.py and irkerbridge.py are vulnerable to symlink attack

Published Jul 28, 2014

Description

The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to gain privileges via a symlink attack on the pid file created for (1) svnwcsub.py or (2) irkerbridge.py when the --pidfile option is used. NOTE: this issue was SPLIT from CVE-2013-4262 based on different affected versions (ADT3).

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of subversion as shipped with Red Hat Enterprise Linux 5 or 6, as they did not ship the vulnerable versions of subversion.

Metrics

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 28, 2014
Updated Aug 6, 2024
Reserved Jul 28, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Aug 30, 2013