cbcvebase.
CVE-2007-2654
published 2007-05-14

CVE-2007-2654: xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs…

PriorityP413medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.34%
25.5th percentile
xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianxfsdump< xfsdump 2.2.45-1 (bookworm)xfsdump 2.2.45-1 (bookworm)
suseopensuse
susesuse_linux
susesuse_linux
susesuse_linux
susesuse_linux_openexchange_server
susesuse_linux_school_server
susesuse_linux_standard_server
susesuse_open_enterprise_server
xfsdumpxfsdump
xfsdumpxfsdump>= 0 < 2.2.45-12.2.45-1
xfsdumpxfsdump>= 0 < 2.2.45-12.2.45-1
xfsdumpxfsdump>= 0 < 2.2.45-12.2.45-1
xfsdumpxfsdump>= 0 < 2.2.45-12.2.45-1

CVSS provenance

nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.