X.Org XFS Init Script Insecure Temporary File Creation Vulnerability
BID:24888
Info
X.Org XFS Init Script Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 24888 |
| Class: | Race Condition Error |
| CVE: |
CVE-2007-3103 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 12 2007 12:00AM |
| Updated: | Apr 13 2015 09:44PM |
| Credit: | An anonymous reporter discovered this issue. This issue as disclosed in the referenced iDefense advisory. |
| Vulnerable: |
X.org xfs 1.0.2 X.org xfs 1.0.1 X.org X11R6 6.8.2 rPath rPath Linux 1 Redhat Fedora Core6 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Gentoo Linux Foresight Linux Foresight Linux 1.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Messaging Storage Server MM3.0 |
| Not Vulnerable: | |
Discussion
X.Org XFS Init Script Insecure Temporary File Creation Vulnerability
The X Font Server (XFS) creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symlink attacks to alter the permissions of an arbitrary attacker-supplied file.
The X Font Server (XFS) creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symlink attacks to alter the permissions of an arbitrary attacker-supplied file.
Exploit / POC
X.Org XFS Init Script Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit the issue.
The following exploit code is available:
An attacker uses readily available commands to exploit the issue.
The following exploit code is available:
Solution / Fix
X.Org XFS Init Script Insecure Temporary File Creation Vulnerability
Solution:
Updates are available. Please see the references for more information.
X.org xfs 1.0.1
Solution:
Updates are available. Please see the references for more information.
X.org xfs 1.0.1
-
Debian xfs_1.0.1-6_alpha.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/x/xfs/xfs_1.0.1-6_alpha.d eb -
Debian xfs_1.0.1-6_amd64.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/x/xfs/xfs_1.0.1-6_amd64.d eb -
Debian xfs_1.0.1-6_arm.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/x/xfs/xfs_1.0.1-6_arm.deb -
Debian xfs_1.0.1-6_hppa.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/x/xfs/xfs_1.0.1-6_hppa.de b -
Debian xfs_1.0.1-6_i386.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/x/xfs/xfs_1.0.1-6_i386.de b -
Debian xfs_1.0.1-6_ia64.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/x/xfs/xfs_1.0.1-6_ia64.de b -
Debian xfs_1.0.1-6_mips.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/x/xfs/xfs_1.0.1-6_mips.de b -
Debian xfs_1.0.1-6_mipsel.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/x/xfs/xfs_1.0.1-6_mipsel. deb -
Debian xfs_1.0.1-6_powerpc.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/x/xfs/xfs_1.0.1-6_powerpc .deb -
Debian xfs_1.0.1-6_s390.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/x/xfs/xfs_1.0.1-6_s390.de b -
Debian xfs_1.0.1-6_sparc.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/x/xfs/xfs_1.0.1-6_sparc.d eb
References
X.Org XFS Init Script Insecure Temporary File Creation Vulnerability
References:
References:
- Bugzilla Bug 242903: CVE-2007-3103 init.d xfs script chown race condition vulner (Red Hat)
- Red Hat Enterprise Linux init.d XFS Script chown Race Condition Vulnerability (iDefense)
- iDefense Security Advisory 07.12.07: Red Hat Enterprise Linux init.d XFS Script (iDefense)
- ASA-2007-324 xorg-x11 security update (RHSA-2007-0519) (Avaya)
- RHSA-2007:0519-2 xorg-x11 security update (Red Hat)
- RHSA-2007:0520-2 xorg-x11-xfs security update (Red Hat)