Apache Subversion CVE-2013-4277 Insecure Temporary File Creation Vulnerability
BID:62266
Info
Apache Subversion CVE-2013-4277 Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 62266 |
| Class: | Design Error |
| CVE: |
CVE-2013-4277 CVE-2013-4277 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 30 2013 12:00AM |
| Updated: | Apr 16 2015 06:14PM |
| Credit: | Daniel Shahaf of elego Software Solutions GmbH |
| Vulnerable: |
Slackware Linux x86_64 -current Slackware Linux -current MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux Apache Software Foundation Subversion 1.6.14 Apache Software Foundation Subversion 1.6.13 Apache Software Foundation Subversion 1.6.12 Apache Software Foundation Subversion 1.6.11 Apache Software Foundation Subversion 1.6.10 Apache Software Foundation Subversion 1.6.6 Apache Software Foundation Subversion 1.6.5 Apache Software Foundation Subversion 1.6.3 Apache Software Foundation Subversion 1.6.2 Apache Software Foundation Subversion 1.5.8 Apache Software Foundation Subversion 1.5.7 Apache Software Foundation Subversion 1.5.5 Apache Software Foundation Subversion 1.5.4 Apache Software Foundation Subversion 1.5.2 Apache Software Foundation Subversion 1.5.1 Apache Software Foundation Subversion 1.4.6 Apache Software Foundation Subversion 1.4.2 Apache Software Foundation Subversion 1.6.9 Apache Software Foundation Subversion 1.6.8 Apache Software Foundation Subversion 1.6.7 Apache Software Foundation Subversion 1.6.4 Apache Software Foundation Subversion 1.6.17 Apache Software Foundation Subversion 1.6.16 Apache Software Foundation Subversion 1.6.15 Apache Software Foundation Subversion 1.6.13 Apache Software Foundation Subversion 1.6.12 Apache Software Foundation Subversion 1.6.11 Apache Software Foundation Subversion 1.6.1 Apache Software Foundation Subversion 1.6.0 Apache Software Foundation Subversion 1.5.6 Apache Software Foundation Subversion 1.5.3 Apache Software Foundation Subversion 1.5.0 Apache Software Foundation Subversion 1.4.5 Apache Software Foundation Subversion 1.4.4 Apache Software Foundation Subversion 1.4.2 Apache Software Foundation Subversion 1.4.1 Apache Software Foundation Subversion 1.4.0 |
| Not Vulnerable: | |
Discussion
Apache Subversion CVE-2013-4277 Insecure Temporary File Creation Vulnerability
Apache Subversion is prone to an insecure temporary-file-creation vulnerability.
Local attackers may be able to perform symbolic-link attacks to overwrite arbitrary files in the context of the affected application. Other attacks may also be possible.
Apache Subversion is prone to an insecure temporary-file-creation vulnerability.
Local attackers may be able to perform symbolic-link attacks to overwrite arbitrary files in the context of the affected application. Other attacks may also be possible.
Exploit / POC
Apache Subversion CVE-2013-4277 Insecure Temporary File Creation Vulnerability
Attackers require local interactive access to exploit this issue.
Attackers require local interactive access to exploit this issue.
Solution / Fix
Apache Subversion CVE-2013-4277 Insecure Temporary File Creation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Subversion CVE-2013-4277 Insecure Temporary File Creation Vulnerability
References:
References:
- CVE-2013-4277 subversion: svnserve is vulnerable to symlink attack (Red Hat)
- Subversion Homepage (Subversion)
- svnserve is vulnerable to a local privilege escalation vulnerability via symlink (Apache Software Foundation)