PT-2007-1097 · Linux+1 · Xfs+1

Vl4Dz

·

Publicado

2007-07-12

·

Atualizado

2018-10-16

·

CVE-2007-3103

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: xfs versions prior to 1.0.5 xfs (affected versions not specified) on various Linux distributions
Description: The issue concerns a potential security risk in the xfs font server package. A local user might exploit this to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file. Multiple vulnerabilities in the xfs package can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations: For xfs versions prior to 1.0.5, update to version 1.0.5 or later to resolve the issue. For xfs on various Linux distributions, consider restricting access to the /tmp/.font-unix temporary file to prevent symlink attacks until a patch is available.

Exploit

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09581
CVE-2007-3103
DSA-1342-1
RHSA-2007:0519
RHSA-2007:0520
RHSA-2007_0519
RHSA-2007_0520

Produtos afetados

Red Hat
Xfs