CVE-2013-6892: Infoleak
Published Jan 18, 2015
·Updated
WebSVN 2.3.3 allows remote authenticated users to read arbitrary files via a symlink attack in a commit.
Affected Software
3 affected components
debian/websvn
WebSVN WebSVN=2.3.3
Debian Debian Linux=7.0
Event History
Jan 18, 2015
Data Sourced
04:42 PM
SeverityAffected Software
Jan 21, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-6892?
CVE-2013-6892 is considered a medium severity vulnerability due to the ability of authenticated users to exploit symlink attacks.
2
How do I fix CVE-2013-6892?
To fix CVE-2013-6892, upgrade WebSVN to a later version that does not allow symlink attacks.
3
Who is affected by CVE-2013-6892?
CVE-2013-6892 affects users of WebSVN version 2.3.3 and Debian Linux version 7.0.
4
What kind of attack does CVE-2013-6892 involve?
CVE-2013-6892 involves a symlink attack that allows remote authenticated users to read arbitrary files.
5
Is authentication required to exploit CVE-2013-6892?
Yes, CVE-2013-6892 requires remote authenticated access to be exploited.