CVE-2007-2654
published 2007-05-14CVE-2007-2654: xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs…
PriorityP413medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.34%
25.5th percentile
xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xfsdump | < xfsdump 2.2.45-1 (bookworm) | xfsdump 2.2.45-1 (bookworm) |
| suse | opensuse | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux | — | — |
| suse | suse_linux_openexchange_server | — | — |
| suse | suse_linux_school_server | — | — |
| suse | suse_linux_standard_server | — | — |
| suse | suse_open_enterprise_server | — | — |
| xfsdump | xfsdump | — | — |
| xfsdump | xfsdump | >= 0 < 2.2.45-1 | 2.2.45-1 |
| xfsdump | xfsdump | >= 0 < 2.2.45-1 | 2.2.45-1 |
| xfsdump | xfsdump | >= 0 < 2.2.45-1 | 2.2.45-1 |
| xfsdump | xfsdump | >= 0 < 2.2.45-1 | 2.2.45-1 |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9gpj-6mg9-3q6q: xfs_fsr in xfsdump creates a
ghsa_unreviewed·2022-05-01
CVE-2007-2654 [MEDIUM] CWE-362 GHSA-9gpj-6mg9-3q6q: xfs_fsr in xfsdump creates a
xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.
OSV
CVE-2007-2654: xfs_fsr in xfsdump creates a
osv·2007-05-14·CVSS 4.4
CVE-2007-2654 [MEDIUM] CVE-2007-2654: xfs_fsr in xfsdump creates a
xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.
Ubuntu
xfsdump vulnerability
vendor_ubuntu·2007-09-20
CVE-2007-2654 xfsdump vulnerability
Title: xfsdump vulnerability
Summary: xfsdump vulnerability
Paul Martin discovered that xfs_fsr creates a temporary directory
with insecure permissions. This allows a local attacker to exploit a
race condition in xfs_fsr to read or overwrite arbitrary files on xfs
filesystems.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2007-2654: xfsdump - xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions,...
vendor_debian·2007·CVSS 4.4
CVE-2007-2654 [MEDIUM] CVE-2007-2654: xfsdump - xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions,...
xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.
Scope: local
bookworm: resolved (fixed in 2.2.45-1)
bullseye: resolved (fixed in 2.2.45-1)
forky: resolved (fixed in 2.2.45-1)
sid: resolved (fixed in 2.2.45-1)
trixie: resolved (fixed in 2.2.45-1)
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=417894http://osvdb.org/36716http://secunia.com/advisories/25220http://secunia.com/advisories/25425http://secunia.com/advisories/25761http://secunia.com/advisories/26867http://www.mandriva.com/security/advisories?name=MDKSA-2007:134http://www.novell.com/linux/security/advisories/2007_10_sr.htmlhttp://www.securityfocus.com/bid/23922http://www.ubuntu.com/usn/usn-516-1http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=417894http://osvdb.org/36716http://secunia.com/advisories/25220http://secunia.com/advisories/25425http://secunia.com/advisories/25761http://secunia.com/advisories/26867http://www.mandriva.com/security/advisories?name=MDKSA-2007:134http://www.novell.com/linux/security/advisories/2007_10_sr.htmlhttp://www.securityfocus.com/bid/23922http://www.ubuntu.com/usn/usn-516-1
2007-05-14
Published