The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to gain privileges via a symlink attack on the pid file created for (1) svnwcsub.py or (2) irkerbridge.py when the –pidfile option is used. NOTE: this issue was SPLIT from CVE-2013-4262 based on different affected versions (ADT3).
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Subversion | Apache | 1.8.0 (including) | 1.8.0 (including) |
Subversion | Apache | 1.8.1 (including) | 1.8.1 (including) |
Subversion | Ubuntu | lucid | * |
Subversion | Ubuntu | upstream | * |