Svnserve in Apache Subversion 1.4.0 through 1.7.12 and 1.8.0 through 1.8.1 allows local users to overwrite arbitrary files or kill arbitrary processes via a symlink attack on the file specified by the --pid-file option.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade subversion | Jul 30, 2024 | Sep 16, 2013 |
| Freebsd | — | Upgrade subversion | Dec 10, 2025 | Sep 2, 2013 |
| Gentoo Linux | — | Upgrade dev-vcs/subversion. | Oct 30, 2017 | Sep 16, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 30, 2013 |
| Suse | — | Upgrade subversion-toolsUpgrade subversion-develUpgrade subversion-pythonUpgrade subversion-perlUpgrade subversion-serverUpgrade libsvn_auth_kwallet-1-0Upgrade subversion-bash-completionUpgrade subversionUpgrade libsvn_auth_gnome_keyring-1-0Upgrade sle-sdk-release | Dec 12, 2013 | Sep 16, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub