CVE-2013-4277: Apache Subversion

Low severity, CVSS 3.3. EPSS: 0.7% chance of exploitation in the next 30 days.

Svnserve in Apache Subversion 1.4.0 through 1.7.12 and 1.8.0 through 1.8.1 allows local users to overwrite arbitrary files or kill arbitrary processes via a symlink attack on the file specified by the --pid-file option.

Affected products

  • Apache Subversion: version 1.4.0 only; version 1.4.1 only; version 1.4.2 only; version 1.4.3 only; version 1.4.4 only; version 1.4.5 only; …

Published 2013-09-16. Last modified 2026-06-16.