{"id":"DEBIAN-CVE-2013-4392","details":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.","modified":"2026-09-01T20:01:59.638107982Z","published":"2013-10-28T22:55:03.773Z","upstream":["CVE-2013-4392"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2013-4392"}],"affected":[{"package":{"name":"systemd","ecosystem":"Debian:12","purl":"pkg:deb/debian/systemd?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["252.11-1","252.11-1~deb12u1","252.12-1~deb12u1","252.14-1~deb12u1","252.16-1~deb12u1","252.17-1~deb12u1","252.18-1~deb12u1","252.19-1~deb12u1","252.20-1~deb12u1","252.21-1~deb12u1","252.22-1~deb12u1","252.23-1~deb12u1","252.24-1~deb12u1","252.25-1~deb12u1","252.26-1~deb12u1","252.26-1~deb12u2","252.26-1~deb12u2~bpo11+1","252.27-1~deb12u1","252.28-1~deb12u1","252.29-1~deb12u1","252.29-1~deb12u1~bpo11+1","252.30-1~deb12u1","252.30-1~deb12u2","252.31-1~deb12u1","252.32-1~deb12u1","252.33-1~deb12u1","252.36-1~deb12u1","252.38-1~deb12u1","252.39-1~deb12u1","252.39-1~deb12u2","252.6-1","252.6-1+loong64","253-1","253-2","253-3","253-4","253.5-1","253~rc2-1","253~rc3-1","254-1","254.1-1","254.1-2","254.1-3","254.14-1~bpo12+1","254.15-1~bpo12+1","254.16-1~bpo12+1","254.22-1~bpo12+1","254.26-1~bpo12+1","254.3-1","254.4-1","254.5-1","254.5-1~bpo12+1","254.5-1~bpo12+2","254.5-1~bpo12+3","254~rc1-1","254~rc1-2","254~rc1-3","254~rc1-4","254~rc2-1","254~rc2-2","254~rc2-3","254~rc3-1","254~rc3-2","254~rc3-3","255-1","255.1-1","255.1-2","255.1-3","255.2-1","255.2-2","255.2-3","255.2-4","255.3-1","255.3-2","255.4-1","255.5-1","255~rc1-1","255~rc1-2","255~rc1-3","255~rc1-4","255~rc2-1","255~rc2-2","255~rc2-3","255~rc3-1","255~rc3-2","255~rc3-3","255~rc4-1","255~rc4-2","256-1","256-2","256.1-1","256.1-2","256.2-1","256.4-1","256.4-2","256.4-3","256.5-1","256.5-2","256.6-1","256.7-1","256.7-2","256.7-3","256~rc1-1~exp","256~rc1-1~exp2","256~rc2-1","256~rc2-2","256~rc2-3","256~rc3-1","256~rc3-2","256~rc3-3","256~rc3-4","256~rc3-5","256~rc3-6","256~rc3-7","256~rc4-1","257-1","257-2","257.1-1","257.1-2","257.1-3","257.1-4","257.1-5","257.1-6","257.1-7","257.13-1~deb13u1","257.2-1","257.2-2","257.2-3","257.3-1","257.4-1","257.4-2","257.4-3","257.4-4","257.4-5","257.4-6","257.4-7","257.4-8","257.4-9","257.5-1","257.5-2","257.6-1","257.7-1","257.8-1~deb13u1","257.8-1~deb13u2","257.9-1~deb13u1","257~rc1-1","257~rc1-2","257~rc1-3","257~rc1-4","257~rc2-1","257~rc2-2","257~rc2-3","257~rc3-1","258-1","258.1-1","258.1-2","258~rc1-1","258~rc2-1","258~rc2-2","258~rc3-1","258~rc4-1","259-1","259.1-1","259~rc1-1","259~rc2-1","259~rc3-1","260-1","260.1-1","260~rc1-1","260~rc1-2","260~rc2-1","260~rc3-1","260~rc4-1","261-1","261-2","261.1-1","261.1-2","261.1-3","261.2-1","261~rc1-1","261~rc2-1","261~rc3-1","261~rc4-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2013-4392.json"}},{"package":{"name":"systemd","ecosystem":"Debian:13","purl":"pkg:deb/debian/systemd?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["257.13-1~deb13u1","257.7-1","257.8-1~deb13u1","257.8-1~deb13u2","257.9-1~deb13u1","258-1","258.1-1","258.1-2","258~rc1-1","258~rc2-1","258~rc2-2","258~rc3-1","258~rc4-1","259-1","259.1-1","259~rc1-1","259~rc2-1","259~rc3-1","260-1","260.1-1","260~rc1-1","260~rc1-2","260~rc2-1","260~rc3-1","260~rc4-1","261-1","261-2","261.1-1","261.1-2","261.1-3","261.2-1","261~rc1-1","261~rc2-1","261~rc3-1","261~rc4-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2013-4392.json"}},{"package":{"name":"systemd","ecosystem":"Debian:14","purl":"pkg:deb/debian/systemd?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["257.13-1~deb13u1","257.7-1","257.8-1~deb13u1","257.8-1~deb13u2","257.9-1~deb13u1","258-1","258.1-1","258.1-2","258~rc1-1","258~rc2-1","258~rc2-2","258~rc3-1","258~rc4-1","259-1","259.1-1","259~rc1-1","259~rc2-1","259~rc3-1","260-1","260.1-1","260~rc1-1","260~rc1-2","260~rc2-1","260~rc3-1","260~rc4-1","261-1","261-2","261.1-1","261.1-2","261.1-3","261.2-1","261~rc1-1","261~rc2-1","261~rc3-1","261~rc4-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2013-4392.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"}]}