LWN.net Logo

subversion: code execution

Package(s):subversion CVE #(s):CVE-2013-2088
Created:June 14, 2013 Updated:June 19, 2013
Description:

From the Novell bug report:

Subversion releases up to 1.6.22 (inclusive), and 1.7.x tags up to 1.7.10 (inclusive, but excepting 1.7.x releases made from those tags), include a contrib/ script prone to shell injection by authenticated users, which could result in arbitrary code execution.

Alerts:
openSUSE openSUSE-SU-2013:1006-1 2013-06-14
openSUSE openSUSE-SU-2013:1139-1 2013-07-04
Fedora FEDORA-2013-13672 2013-08-15
Gentoo 201309-11 2013-09-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds