Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-2088
HistoryJul 31, 2013 - 12:00 a.m.

CVE-2013-2088

2013-07-3100:00:00
ubuntu.com
ubuntu.com
18

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:S/C:C/I:C/A:C

0.015 Low

EPSS

Percentile

87.2%

contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23
allows remote authenticated users with commit permissions to execute
arbitrary commands via shell metacharacters in a filename.

Notes

Author Note
jdstrand per Debian, affected tools not shipped in binary packages

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:S/C:C/I:C/A:C

0.015 Low

EPSS

Percentile

87.2%