CVE-2013-4510

high
Published 2013-11-18 · Modified 2024-05-01
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v2
7.8
VIR risk
7.8

Description

Directory traversal vulnerability in the client in Tryton 3.0.0, as distributed before 20131104 and earlier, allows remote servers to write arbitrary files via path separators in the extension of a report.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-4510

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugs.tryton.org/issue3446

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.tryton.org/posts/security-release-for-issue3446.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://hg.tryton.org/tryton/rev/357d0a4d9cb8

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.8.4-1
debian debianbullseyefixed2.8.4-1
debian debianforkyfixed2.8.4-1
debian debiansidfixed2.8.4-1
debian debiantrixiefixed2.8.4-1

Package impact

EcosystemPackageVulnerableFixed
python PyPItrytond
python PyPItryton<3.0.13.0.1

Application impact

VendorProductVersionsFixed
trytontryton3.0.0

References

CWEs

CWE-22

Verify integrity in audit chain (admin only). AS-IS.