Wind River Support Network

HomeDefectsLIN7-63
Fixed

LIN7-63 : Security Advisory - subversion - CVE-2013-4277

Created: May 15, 2014    Updated: Mar 31, 2016
Resolved Date: Jun 11, 2014
Found In Version: 7.0.0.0.LB08
Fix Version: 7.0
Severity: Low
Applicable for: Wind River Linux 7
Component/s: Userspace

Description

Svnserve in Apache Subversion 1.4.0 through 1.7.12 and 1.8.0 through 1.8.1 allows local users to overwrite arbitrary files or kill arbitrary processes via a symlink attack on the file specified by the --pid-file option.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4277

Workaround

Unknown

Steps to Reproduce

Unknown
Live chat
Online