Bug 1000202 (CVE-2013-4277) - CVE-2013-4277 subversion: svnserve is vulnerable to symlink attack
Summary: CVE-2013-4277 subversion: svnserve is vulnerable to symlink attack
Alias: CVE-2013-4277
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 1003070 1003071
Blocks: 1000203
TreeView+ depends on / blocked
Reported: 2013-08-22 22:48 UTC by Vincent Danen
Modified: 2023-05-11 23:46 UTC (History)
3 users (show)

Fixed In Version: subversion 1.7.12, subversion 1.8.3
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2014-02-13 04:54:01 UTC

Attachments (Terms of Use)
upstream patch to fix CVE-2013-4277 in subversion 1.8.x (816 bytes, patch)
2013-08-22 22:50 UTC, Vincent Danen
no flags Details | Diff

Description Vincent Danen 2013-08-22 22:48:14 UTC
It was reported that the Subversion svnserve daemon is vulnerable to a symlink attack when the --pid-file argument is passed to it.  If the PID file were written in a directory that is writable by an unprivileged user, that user could create a symlink to a file that would be overwritten with the privilges of the svnserve daemon (typically root).  As well, because the initscripts read the contents of the file to determine which process to kill on service shutdown, if it were symlinked to a file writable by the local user, they could replace the contents of the file with another application's pid, which would cause a different application to be killed when the svnserve initscript is called to stop the service.

By default, Red Hat Enterprise Linux and Fedora call svnserve with '--pid-file=/run/svnserve/svnserve.pid' (Fedora) or '--pid-file=/var/run/svnserve.pid' (Red Hat Enterprise Linux).  These directories are not writable by unprivileged users.


Red Hat would like to thank Ben Reser of the Apache Subversion project for reporting this issue. Upstream acknowledges Daniel Shahaf of elego Software Solutions GmbH as the original issue reporter.

Comment 1 Vincent Danen 2013-08-22 22:49:13 UTC
This issue is embargoed until 29 August 2013 17:00 UTC.

Comment 2 Vincent Danen 2013-08-22 22:50:12 UTC
Created attachment 789398 [details]
upstream patch to fix CVE-2013-4277 in subversion 1.8.x

Comment 5 Vincent Danen 2013-08-30 16:46:19 UTC
External References:


Comment 8 Vincent Danen 2013-08-30 16:52:23 UTC
Created subversion tracking bugs for this issue:

Affects: fedora-all [bug 1003070]

Comment 9 Fedora Update System 2013-09-08 00:33:16 UTC
subversion-1.7.13-1.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 10 Huzaifa S. Sidhpurwala 2014-02-13 04:50:18 UTC
As mentioned in comment #0, Red Hat and Fedora versions of subversion package are not vulnerable to this issue, because they create the pid files at a secure location (not writable by unprivileged users).

The only way this flaw could be exploited was if a root user changed the default location of the creation of pid files via "/etc/sysconfig/svnserve" or "/etc/init.d/svnserve" to a directory writable by unprivileged users.

Therefore, The Red Hat Security Response Team, does not consider this issue as a security flaw.

Comment 11 Huzaifa S. Sidhpurwala 2014-02-13 04:54:01 UTC

The Red Hat Security Response Team does not consider this issue to be a security flaw. For technical details please refer to https://bugzilla.redhat.com/show_bug.cgi?id=1000202#c10

Note You need to log in before you can comment on or make changes to this bug.