VDB

GCVE-110-MAGEIA-2013-275

GCVE-110-MAGEIA-2013-275
Advisory Published
Vulnetix · Advisory published September 13, 2013
svnserve takes a --pid-file option which creates a file containing the process id it is running as. It does not take steps to ensure that the file it has been directed at is not a symlink. If the pid file is in a directory writeable by unprivileged users, the destination could be replaced by a symlink allowing for privilege escalation. svnserve does not create a pid file by default (CVE-2013-4277).

Affected Products

VendorProductVersionsPlatforms
Mageiasubversion0 (affected), 1.7.13-1.mga3 (unaffected)
Mageiasubversion0 (affected), 1.7.13-1.mga2 (unaffected)

Browse GCVE Records

67,893 records in the GCVE database · Updated August 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›