Advisories ยป MGASA-2013-0275

Updated subversion package fixes security vulnerability.

Publication date: 13 Sep 2013
Modification date: 13 Sep 2013
Type: security
Affected Mageia releases : 2 , 3
CVE: CVE-2013-4277

Description

svnserve takes a --pid-file option which creates a file containing the
process id it is running as. It does not take steps to ensure that the
file it has been directed at is not a symlink. If the pid file is in a
directory writeable by unprivileged users, the destination could be
replaced by a symlink allowing for   privilege escalation. svnserve
does not create a pid file by default (CVE-2013-4277).
                

References

SRPMS

2/core

3/core