CVE-2013-2088: Input Validation
Published Jul 31, 2013
·Updated
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.
Affected Software
24 affected components
Apache subversion<=1.6.21
Apache subversion=1.6.0
Apache subversion=1.6.1
Apache subversion=1.6.2
Apache subversion=1.6.3
Apache subversion=1.6.4
Apache subversion=1.6.5
Apache subversion=1.6.6
Apache subversion=1.6.7
Apache subversion=1.6.8
Apache subversion=1.6.9
Apache subversion=1.6.10
Apache subversion=1.6.11
Apache subversion=1.6.12
Apache subversion=1.6.13
Apache subversion=1.6.14
Apache subversion=1.6.15
Apache subversion=1.6.16
Apache subversion=1.6.17
Apache subversion=1.6.18
Apache subversion=1.6.19
Apache subversion=1.6.20
CollabNet Subversion=1.6.17
openSUSE openSUSE=11.4
Event History
Jul 31, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2088?
CVE-2013-2088 has been rated as a moderate severity vulnerability.
2
How do I fix CVE-2013-2088?
To fix CVE-2013-2088, upgrade to Subversion version 1.6.23 or later.
3
Who is affected by CVE-2013-2088?
CVE-2013-2088 affects all versions of Subversion prior to 1.6.23, specifically impacting users with commit permissions.
4
What type of attack does CVE-2013-2088 enable?
CVE-2013-2088 allows remote authenticated users to execute arbitrary commands through shell metacharacters in a filename.
5
Is CVE-2013-2088 a local or remote vulnerability?
CVE-2013-2088 is categorized as a remote vulnerability, as it involves authenticated remote users.