CVE-2013-2088
EPSS 6.5%
Description
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.
How to fix CVE-2013-2088
To remediate CVE-2013-2088, upgrade the affected package to a fixed version below.
- Debian/subversion—upgrade to 1.7.5-1 or later
Is CVE-2013-2088 being exploited?
Moderate — EPSS is 6.5%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1.7.5-1