cbcvebase.
CVE-2007-2654
published 2007-05-14

CVE-2007-2654: xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs…

medium4.4CVSS 3.1
AVLACMAuNCPIPAP
xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianxfsdump< xfsdump 2.2.45-1 (bookworm)xfsdump 2.2.45-1 (bookworm)
suseopensuse
susesuse_linux
susesuse_linux
susesuse_linux
susesuse_linux_openexchange_server
susesuse_linux_school_server
susesuse_linux_standard_server
susesuse_open_enterprise_server
xfsdumpxfsdump
xfsdumpxfsdump>= 0 < 2.2.45-12.2.45-1
xfsdumpxfsdump>= 0 < 2.2.45-12.2.45-1
xfsdumpxfsdump>= 0 < 2.2.45-12.2.45-1
xfsdumpxfsdump>= 0 < 2.2.45-12.2.45-1

CVSS provenance

nvd4.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM