CVE-2013-4262: Apache Subversion

Low severity, CVSS 2.4. EPSS: 0.6% chance of exploitation in the next 30 days.

svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the --pidfile option and running in foreground mode, allows local users to gain privileges via a symlink attack on the pid file. NOTE: this issue was SPLIT due to different affected versions (ADT3). The irkerbridge.py issue is covered by CVE-2013-7393.

Affected products

  • Apache Subversion: version 1.8.0 only; version 1.8.1 only; version 1.8.2 only

Published 2014-07-28. Last modified 2026-06-16.