VulnerabilityModified
CVE-2013-4277
Svnserve in Apache Subversion 1.4.0 through 1.7.12 and 1.8.0 through 1.8.1 allows local users to overwrite arbitrary files or kill arbitrary processes via a symlink attack on the file specified by the --pid-file option.
LOW 3.3EPSS 0.69%
Does this matter?
Lower severity and a low EPSS score (0.69%). Track it; it rarely justifies an emergency change on its own.
Description
Svnserve in Apache Subversion 1.4.0 through 1.7.12 and 1.8.0 through 1.8.1 allows local users to overwrite arbitrary files or kill arbitrary processes via a symlink attack on the file specified by the --pid-file option.
- CVSS 2.0
- 3.3 LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- apache/subversion
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-updates/2013-09/msg00031.html
- http://lists.opensuse.org/opensuse-updates/2013-09/msg00054.html
- http://subversion.apache.org/security/CVE-2013-4277-advisory.txtVendor Advisory
- http://www.securityfocus.com/bid/62266
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86972
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18554
- http://lists.opensuse.org/opensuse-updates/2013-09/msg00031.html
- http://lists.opensuse.org/opensuse-updates/2013-09/msg00054.html
- http://subversion.apache.org/security/CVE-2013-4277-advisory.txtVendor Advisory
- http://www.securityfocus.com/bid/62266
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86972
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18554
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.