SGI XFSDump Quotas File Symbolic Link Vulnerability
BID:7321
Info
SGI XFSDump Quotas File Symbolic Link Vulnerability
| Bugtraq ID: | 7321 |
| Class: | Design Error |
| CVE: |
CVE-2003-0173 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 10 2003 12:00AM |
| Updated: | Jul 11 2009 09:06PM |
| Credit: | Discovery credited to Ethan Benson, Nathan Scott and Debian. |
| Vulnerable: |
xfsdump xfsdump 2.0.5 xfsdump xfsdump 2.0.4 xfsdump xfsdump 2.0.3 xfsdump xfsdump 2.0.2 xfsdump xfsdump 2.0.1 xfsdump xfsdump 2.0 SGI IRIX 6.5.19 SGI IRIX 6.5.18 m SGI IRIX 6.5.18 f SGI IRIX 6.5.18 SGI IRIX 6.5.17 m SGI IRIX 6.5.17 f SGI IRIX 6.5.17 SGI IRIX 6.5.16 m SGI IRIX 6.5.16 f SGI IRIX 6.5.16 SGI IRIX 6.5.15 m SGI IRIX 6.5.15 f SGI IRIX 6.5.15 SGI IRIX 6.5.14 m SGI IRIX 6.5.14 f SGI IRIX 6.5.14 SGI IRIX 6.5.13 m SGI IRIX 6.5.13 f SGI IRIX 6.5.13 SGI IRIX 6.5.12 m SGI IRIX 6.5.12 f SGI IRIX 6.5.12 SGI IRIX 6.5.11 m SGI IRIX 6.5.11 f SGI IRIX 6.5.11 SGI IRIX 6.5.10 m SGI IRIX 6.5.10 f SGI IRIX 6.5.10 SGI IRIX 6.5.9 m SGI IRIX 6.5.9 f SGI IRIX 6.5.9 SGI IRIX 6.5.8 m SGI IRIX 6.5.8 f SGI IRIX 6.5.8 SGI IRIX 6.5.7 m SGI IRIX 6.5.7 f SGI IRIX 6.5.7 SGI IRIX 6.5.6 m SGI IRIX 6.5.6 f SGI IRIX 6.5.6 SGI IRIX 6.5.5 m SGI IRIX 6.5.5 f SGI IRIX 6.5.5 SGI IRIX 6.5.4 m SGI IRIX 6.5.4 f SGI IRIX 6.5.4 SGI IRIX 6.5.3 m SGI IRIX 6.5.3 f SGI IRIX 6.5.3 SGI IRIX 6.5.2 m SGI IRIX 6.5.2 f SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 .19m SGI IRIX 6.5 .19f SGI IRIX 6.5 SGI IRIX 6.4 SGI IRIX 6.3 SGI IRIX 6.2 SGI IRIX 6.1 SGI IRIX 6.0.1 XFS SGI IRIX 6.0.1 SGI IRIX 6.0 SGI IRIX 5.3 XFS SGI IRIX 5.3 SGI IRIX 5.2 SGI IRIX 5.1.1 SGI IRIX 5.1 SGI IRIX 5.0.1 SGI IRIX 5.0 SGI IRIX 4.0.5 IPR SGI IRIX 4.0.5 H SGI IRIX 4.0.5 G SGI IRIX 4.0.5 F SGI IRIX 4.0.5 E SGI IRIX 4.0.5 D SGI IRIX 4.0.5 A SGI IRIX 4.0.5 SGI IRIX 4.0.4 T SGI IRIX 4.0.4 SGI IRIX 4.0.3 SGI IRIX 4.0.2 SGI IRIX 4.0.1 SGI IRIX 4.0 SGI IRIX 3.3.3 SGI IRIX 3.3.2 SGI IRIX 3.3.1 SGI IRIX 3.3 SGI IRIX 3.2 |
| Not Vulnerable: |
SGI IRIX 6.5.20 |
Exploit / POC
SGI XFSDump Quotas File Symbolic Link Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
SGI XFSDump Quotas File Symbolic Link Vulnerability
Solution:
Debian has released a security advisory (DSA 283-1) containing fixes which address this issue.
Mandrake has released a security advisory (MDKSA-2003:047) which contains fixes for this issue. Users are advised to upgrade as soon as possible.
SGI has released advisory 20030404-01-P, and made fixes available to address this issue:
xfsdump xfsdump 2.0
xfsdump xfsdump 2.0.1
xfsdump xfsdump 2.0.3
xfsdump xfsdump 2.0.5
SGI IRIX 6.5 .19f
SGI IRIX 6.5 .19m
SGI IRIX 6.5.16 f
SGI IRIX 6.5.16 m
SGI IRIX 6.5.17 m
SGI IRIX 6.5.17 f
SGI IRIX 6.5.18 m
SGI IRIX 6.5.18 f
Solution:
Debian has released a security advisory (DSA 283-1) containing fixes which address this issue.
Mandrake has released a security advisory (MDKSA-2003:047) which contains fixes for this issue. Users are advised to upgrade as soon as possible.
SGI has released advisory 20030404-01-P, and made fixes available to address this issue:
xfsdump xfsdump 2.0
-
Mandrake xfsdump-2.0.0-2.1mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xfsdump-2.0.0-2.1mdk.ppc.rpm
Mandrake Linux 8.2/PPC
http://www.mandrakesecure.net/en/ftp.php
xfsdump xfsdump 2.0.1
-
Debian xfsdump_2.0.1-2_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfsdump/xfsdump_2.0.1-2 _alpha.deb -
Debian xfsdump_2.0.1-2_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfsdump/xfsdump_2.0.1-2 _arm.deb -
Debian xfsdump_2.0.1-2_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfsdump/xfsdump_2.0.1-2 _hppa.deb -
Debian xfsdump_2.0.1-2_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfsdump/xfsdump_2.0.1-2 _i386.deb -
Debian xfsdump_2.0.1-2_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfsdump/xfsdump_2.0.1-2 _ia64.deb -
Debian xfsdump_2.0.1-2_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfsdump/xfsdump_2.0.1-2 _m68k.deb -
Debian xfsdump_2.0.1-2_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfsdump/xfsdump_2.0.1-2 _mips.deb -
Debian xfsdump_2.0.1-2_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfsdump/xfsdump_2.0.1-2 _mipsel.deb -
Debian xfsdump_2.0.1-2_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfsdump/xfsdump_2.0.1-2 _powerpc.deb -
Debian xfsdump_2.0.1-2_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfsdump/xfsdump_2.0.1-2 _s390.deb -
Debian xfsdump_2.0.1-2_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/x/xfsdump/xfsdump_2.0.1-2 _sparc.deb
xfsdump xfsdump 2.0.3
-
Mandrake xfsdump-2.0.3-1.1mdk.i586.rpm
Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xfsdump-2.0.3-1.1mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php
xfsdump xfsdump 2.0.5
-
Mandrake libdm0-2.0.5-1.2mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libdm0-2.0.5-1.2mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libdm0-devel-2.0.5-1.2mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libdm0-devel-2.0.5-1.2mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xfsdump-2.0.3-1.1mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xfsdump-2.0.3-1.1mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php
SGI IRIX 6.5 .19f
SGI IRIX 6.5 .19m
SGI IRIX 6.5.16 f
SGI IRIX 6.5.16 m
SGI IRIX 6.5.17 m
SGI IRIX 6.5.17 f
SGI IRIX 6.5.18 m
SGI IRIX 6.5.18 f
References
SGI XFSDump Quotas File Symbolic Link Vulnerability
References:
References: