CVE-2013-4277: Low severity subversion vulnerability
Svnserve in Apache Subversion 1.4.0 through 1.7.12 and 1.8.0 through 1.8.1 allows local users to overwrite arbitrary files or kill arbitrary processes via a symlink attack on the file specified by the --pid-file option.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4277?
CVE-2013-4277 has a moderate severity due to its potential for local users to compromise system integrity through a symlink attack.
How do I fix CVE-2013-4277?
To mitigate CVE-2013-4277, update Apache Subversion to a version later than 1.8.1 that addresses this vulnerability.
Which versions of Apache Subversion are affected by CVE-2013-4277?
CVE-2013-4277 affects Apache Subversion versions 1.4.0 through 1.7.12 and 1.8.0 through 1.8.1.
What kind of attack does CVE-2013-4277 involve?
CVE-2013-4277 involves a symlink attack that allows local users to overwrite files or terminate processes.
Can CVE-2013-4277 be exploited remotely?
No, CVE-2013-4277 can only be exploited locally by authenticated users with access to the system.