LWN.net Logo

Advertisement

GStreamer, Embedded Linux, Android, VoD, Smooth Streaming, DRM, RTSP, HEVC, PulseAudio, OpenGL. Register now to attend.

Advertise here

subversion: privilege escalation

Package(s):subversion CVE #(s):CVE-2013-4277
Created:September 9, 2013 Updated:September 25, 2013
Description: From the Fedora advisory:

svnserve takes a --pid-file option which creates a file containing the process id it is running as. It does not take steps to ensure that the file it has been directed at is not a symlink. If the pid file is in a directory writeable by unprivileged users, the destination could be replaced by a symlink allowing for privilege escalation. svnserve does not create a pid file by default.

Alerts:
Fedora FEDORA-2013-15717 2013-09-08
Slackware SSA:2013-251-01 2013-09-09
openSUSE openSUSE-SU-2013:1442-1 2013-09-13
Mandriva MDVSA-2013:236 2013-09-17
Mageia MGASA-2013-0275 2013-09-13
Gentoo 201309-11 2013-09-23
openSUSE openSUSE-SU-2013:1485-1 2013-09-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds