CVE-2013-0219

low
Published 2013-02-24 · Modified 2026-04-29
CVSS v3
CVSS v2
3.7
VIR risk
3.7

Description

System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-0219

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/52315

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/51928

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2013-0219.html

OS impact

OSVersionStatusFixed in
suse slesaffected
redhat rhel5affected
redhat rhel6.0affected
debian debianbookwormfixed1.8.4-2
debian debianbullseyefixed1.8.4-2
debian debiansidfixed1.8.4-2
debian debiantrixiefixed1.8.4-2

Application impact

VendorProductVersionsFixed
fedoraprojectsssd{"endIncluding":"1.9.3"}
fedoraprojectsssd0.2.1
fedoraprojectsssd0.3.0
fedoraprojectsssd0.3.1
fedoraprojectsssd0.3.2
fedoraprojectsssd0.3.3
fedoraprojectsssd0.4.0
fedoraprojectsssd0.4.1
fedoraprojectsssd0.5.0
fedoraprojectsssd0.6.0
fedoraprojectsssd0.6.1
fedoraprojectsssd0.7.0
fedoraprojectsssd0.7.1
fedoraprojectsssd0.99.0
fedoraprojectsssd0.99.1
fedoraprojectsssd1.0.0
fedoraprojectsssd1.0.1
fedoraprojectsssd1.0.2
fedoraprojectsssd1.0.3
fedoraprojectsssd1.0.4
fedoraprojectsssd1.0.5
fedoraprojectsssd1.0.6
fedoraprojectsssd1.0.99
fedoraprojectsssd1.1.0
fedoraprojectsssd1.1.1
fedoraprojectsssd1.1.2
fedoraprojectsssd1.1.91
fedoraprojectsssd1.1.92
fedoraprojectsssd1.2.0
fedoraprojectsssd1.2.1
fedoraprojectsssd1.2.2
fedoraprojectsssd1.2.3
fedoraprojectsssd1.2.4
fedoraprojectsssd1.2.91
fedoraprojectsssd1.3.0
fedoraprojectsssd1.3.1
fedoraprojectsssd1.4.0
fedoraprojectsssd1.4.1
fedoraprojectsssd1.5.0
fedoraprojectsssd1.5.1
fedoraprojectsssd1.5.2
fedoraprojectsssd1.5.3
fedoraprojectsssd1.5.4
fedoraprojectsssd1.5.5
fedoraprojectsssd1.5.6
fedoraprojectsssd1.5.6.1
fedoraprojectsssd1.5.7
fedoraprojectsssd1.5.8
fedoraprojectsssd1.5.9
fedoraprojectsssd1.5.10
fedoraprojectsssd1.5.11
fedoraprojectsssd1.5.12
fedoraprojectsssd1.5.13
fedoraprojectsssd1.5.14
fedoraprojectsssd1.5.15
fedoraprojectsssd1.5.16
fedoraprojectsssd1.5.17
fedoraprojectsssd1.6.0
fedoraprojectsssd1.6.1
fedoraprojectsssd1.6.2
fedoraprojectsssd1.6.3
fedoraprojectsssd1.6.4
fedoraprojectsssd1.7.0
fedoraprojectsssd1.8.0
fedoraprojectsssd1.8.1
fedoraprojectsssd1.8.2
fedoraprojectsssd1.8.3
fedoraprojectsssd1.8.4
fedoraprojectsssd1.8.5
fedoraprojectsssd1.8.6
fedoraprojectsssd1.9.0
fedoraprojectsssd1.9.1
fedoraprojectsssd1.9.2

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.