CVE-2013-1423

(1) contrib/gforge-3.0-cronjobs.patch, (2) cronjobs/homedirs.php, (3) deb-specific/fileforge.pl, (4) deb-specific/group_dump_update.pl, (5) deb-specific/ssh_dump_update.pl, (6) deb-specific/user_dump_update.pl, (7) plugins/scmbzr/common/BzrPlugin.class.php, (8) plugins/scmcvs/common/CVSPlugin.class.php, (9) plugins/scmcvs/cronjobs/cvs.php, (10) plugins/scmcvs/cronjobs/ssh_create.php, (11) plugins/scmgit/common/GitPlugin.class.php, (12) plugins/scmsvn/common/SVNPlugin.class.php, (13) plugins/wiki/cronjobs/create_groups.php, (14) utils/cvs1/cvscreate.sh, and (15) utils/include.pl in FusionForge 5.0, 5.1, and 5.2 allows local users to change arbitrary file permissions, obtain sensitive information, and have other unspecified impacts via a (1) symlink or (2) hard link attack on certain files.

Published: 2013-03-14 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2013-1423 is rated Low Risk (28.3/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.04%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2013-1423

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2023-03-07 1.28% 0.04% -1.24%
2 2022-02-04 1.28%

Full EPSS history (2 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2013-1423

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.9 2.0 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
3.4 10.0 [email protected]

Weakness enumeration for CVE-2013-1423

OS Trackers for CVE-2013-1423

vendor priority summary link
ubuntu medium CVE-2013-1423 medium priority: Ubuntu including 1 source packages (fusionforge), 15 status rows across 15 suites (hardy, lucid, oneiric, precise, quantal, raring, saucy, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): DNE 7, not-affected 4, ignored 3, needs-triage 1. https://ubuntu.com/security/CVE-2013-1423

Affected software / configurations for CVE-2013-1423

Vendor Product Version Raw CPE
fusionforge fusionforge 5.0 cpe:2.3:a:fusionforge:fusionforge:5.0:*:*:*:*:*:*:*
fusionforge fusionforge 5.1 cpe:2.3:a:fusionforge:fusionforge:5.1:*:*:*:*:*:*:*
fusionforge fusionforge 5.2 cpe:2.3:a:fusionforge:fusionforge:5.2:*:*:*:*:*:*:*

References for CVE-2013-1423

cvelogic Threat Intelligence