2.4
CVSSv2

CVE-2013-7393

Published: 28/07/2014 Updated: 18/10/2016
CVSS v2 Base Score: 2.4 | Impact Score: 4.9 | Exploitability Score: 1.5
VMScore: 214
Vector: AV:L/AC:H/Au:S/C:N/I:P/A:P

Vulnerability Summary

The daemonize.py module in Subversion 1.8.0 prior to 1.8.2 allows local users to gain privileges via a symlink attack on the pid file created for (1) svnwcsub.py or (2) irkerbridge.py when the --pidfile option is used. NOTE: this issue was SPLIT from CVE-2013-4262 based on different affected versions (ADT3).

Vulnerable Product Search on Vulmon Subscribe to Product

apache subversion 1.8.0

apache subversion 1.8.1

Vendor Advisories

The daemonizepy module in Subversion 180 before 182 allows local users to gain privileges via a symlink attack on the pid file created for (1) svnwcsubpy or (2) irkerbridgepy when the --pidfile option is used NOTE: this issue was SPLIT from CVE-2013-4262 based on different affected versions (ADT3) ...