svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the –pidfile option and running in foreground mode, allows local users to gain privileges via a symlink attack on the pid file. NOTE: this issue was SPLIT due to different affected versions (ADT3). The irkerbridge.py issue is covered by CVE-2013-7393.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Subversion | Apache | 1.8.0 (including) | 1.8.0 (including) |
Subversion | Apache | 1.8.1 (including) | 1.8.1 (including) |
Subversion | Apache | 1.8.2 (including) | 1.8.2 (including) |
Subversion | Ubuntu | lucid | * |
Subversion | Ubuntu | upstream | * |