xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 00:31
Type | Values Removed | Values Added |
---|---|---|
References | () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=417894 - Exploit | |
References | () http://osvdb.org/36716 - | |
References | () http://secunia.com/advisories/25220 - Vendor Advisory | |
References | () http://secunia.com/advisories/25425 - Vendor Advisory | |
References | () http://secunia.com/advisories/25761 - Vendor Advisory | |
References | () http://secunia.com/advisories/26867 - Vendor Advisory | |
References | () http://www.mandriva.com/security/advisories?name=MDKSA-2007:134 - | |
References | () http://www.novell.com/linux/security/advisories/2007_10_sr.html - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/23922 - | |
References | () http://www.ubuntu.com/usn/usn-516-1 - |
Information
Published : 2007-05-14 21:19
Updated : 2024-11-21 00:31
NVD link : CVE-2007-2654
Mitre link : CVE-2007-2654
CVE.ORG link : CVE-2007-2654
JSON object : View
Products Affected
suse
- suse_united_linux
- opensuse
- suse_linux_openexchange_server
- suse_linux
- suse_linux_standard_server
- suse_linux_school_server
- suse_open_enterprise_server
xfsdump
- xfsdump
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')