xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.
CVSS Vector
AV:L/AC:M/Au:N/C:P/I:P/A:PSUSE Opensuse
OSSuse10.2SUSE Linux
OSSuse1.01010.010.110.288.09.09.19.29.3SUSE Linux Openexchange Server
APPSuse4.0SUSE Linux School Server
APPSusegoldSUSE Linux Standard Server
APPSuse8.0SUSE Open Enterprise Server
APPSuse9SUSE United Linux
OSSuse1.0Xfsdump
APPXfsdump2.2.38
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
Related vulnerabilities
CVE-2011-0469CRITICAL9.8PL ✓same product
Code injection w openSUSE Open Build Service 2.1 (przed 11 marca 2011)
CVE-2002-0083CRITICAL9.8PL ✓same product
OpenSSH: błąd off-by-one w kodzie kanałów umożliwia eskalację uprawnień
CVE-1999-0426CRITICAL9.8PL ✓same product
Nieprawidłowe uprawnienia /dev/kmem umożliwiają IP spoofing w Linux
CVE-2024-12085HIGH7.5same product
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an att...
CVE-2017-3224HIGH8.2same product
Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LS...