PT-2007-1097 · Linux+1 · Xfs+1

Vl4Dz

·

Published

2007-07-12

·

Updated

2018-10-16

·

CVE-2007-3103

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: xfs versions prior to 1.0.5 xfs (affected versions not specified) on various Linux distributions
Description: The issue concerns a potential security risk in the xfs font server package. A local user might exploit this to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file. Multiple vulnerabilities in the xfs package can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations: For xfs versions prior to 1.0.5, update to version 1.0.5 or later to resolve the issue. For xfs on various Linux distributions, consider restricting access to the /tmp/.font-unix temporary file to prevent symlink attacks until a patch is available.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09581
CVE-2007-3103
DSA-1342-1
RHSA-2007:0519
RHSA-2007:0520
RHSA-2007_0519
RHSA-2007_0520

Affected Products

Red Hat
Xfs