xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2007-05-14 21:19
Updated : 2025-04-09 00:30
NVD link : CVE-2007-2654
Mitre link : CVE-2007-2654
CVE.ORG link : CVE-2007-2654
JSON object : View
Products Affected
suse
- suse_linux_school_server
- suse_linux_standard_server
- suse_united_linux
- suse_linux_openexchange_server
- opensuse
- suse_linux
- suse_open_enterprise_server
xfsdump
- xfsdump
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')