CVE-2007-2654

xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:suse:suse_linux:1.0:*:desktop:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:8:*:enterprise_server:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:8.0:*:retail_solution:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.0:*:enterprise_server:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.0:*:personal:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.0:*:professional:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.0:*:x86_64:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.1:*:personal:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.1:*:professional:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.1:*:x86_64:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.2:*:personal:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.2:*:professional:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.2:*:x86_64:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.3:*:personal:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.3:*:professional:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.3:*:x86_64:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:10:*:enterprise_desktop:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:10:*:enterprise_server:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:10.0:*:oss:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:10.1:*:personal:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:10.1:*:professional:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:10.2:*:professional:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:10.2:*:x86_64:*:*:*:*:*
cpe:2.3:o:suse:suse_united_linux:1.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:suse:suse_linux_openexchange_server:4.0:*:*:*:*:*:*:*
cpe:2.3:a:suse:suse_linux_school_server:gold:*:i386:*:*:*:*:*
cpe:2.3:a:suse:suse_linux_standard_server:8.0:*:*:*:*:*:*:*
cpe:2.3:a:suse:suse_open_enterprise_server:9:*:*:*:*:*:*:*
cpe:2.3:a:xfsdump:xfsdump:2.2.38:*:*:*:*:*:*:*
cpe:2.3:o:suse:opensuse:10.2:*:*:*:*:*:*:*

History

21 Nov 2024, 00:31

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=417894 - Exploit () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=417894 - Exploit
References () http://osvdb.org/36716 - () http://osvdb.org/36716 -
References () http://secunia.com/advisories/25220 - Vendor Advisory () http://secunia.com/advisories/25220 - Vendor Advisory
References () http://secunia.com/advisories/25425 - Vendor Advisory () http://secunia.com/advisories/25425 - Vendor Advisory
References () http://secunia.com/advisories/25761 - Vendor Advisory () http://secunia.com/advisories/25761 - Vendor Advisory
References () http://secunia.com/advisories/26867 - Vendor Advisory () http://secunia.com/advisories/26867 - Vendor Advisory
References () http://www.mandriva.com/security/advisories?name=MDKSA-2007:134 - () http://www.mandriva.com/security/advisories?name=MDKSA-2007:134 -
References () http://www.novell.com/linux/security/advisories/2007_10_sr.html - Vendor Advisory () http://www.novell.com/linux/security/advisories/2007_10_sr.html - Vendor Advisory
References () http://www.securityfocus.com/bid/23922 - () http://www.securityfocus.com/bid/23922 -
References () http://www.ubuntu.com/usn/usn-516-1 - () http://www.ubuntu.com/usn/usn-516-1 -

Information

Published : 2007-05-14 21:19

Updated : 2024-11-21 00:31


NVD link : CVE-2007-2654

Mitre link : CVE-2007-2654

CVE.ORG link : CVE-2007-2654


JSON object : View

Products Affected

suse

  • suse_united_linux
  • opensuse
  • suse_linux_openexchange_server
  • suse_linux
  • suse_linux_standard_server
  • suse_linux_school_server
  • suse_open_enterprise_server

xfsdump

  • xfsdump
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')