CVE-2013-4262: Apache Subversion
Low severity, CVSS 2.4. EPSS: 0.6% chance of exploitation in the next 30 days.
svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the --pidfile option and running in foreground mode, allows local users to gain privileges via a symlink attack on the pid file. NOTE: this issue was SPLIT due to different affected versions (ADT3). The irkerbridge.py issue is covered by CVE-2013-7393.
Affected products
- Apache Subversion: version 1.8.0 only; version 1.8.1 only; version 1.8.2 only
Published 2014-07-28. Last modified 2026-06-16.