[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-7393Date: (C)2014-07-30   (M)2023-12-22


The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to gain privileges via a symlink attack on the pid file created for (1) svnwcsub.py or (2) irkerbridge.py when the --pidfile option is used. NOTE: this issue was SPLIT from CVE-2013-4262 based on different affected versions (ADT3).

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.4
Exploit Score: 1.5
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: HIGH
Authentication: SINGLE
Confidentiality: NONE
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
https://subversion.apache.org/security/CVE-2013-4262-advisory.txt

CPE    2
cpe:/a:apache:subversion:1.8.0
cpe:/a:apache:subversion:1.8.1
CWE    1
CWE-59
OVAL    1
oval:org.secpod.oval:def:20663

© SecPod Technologies