Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2007-3103

CWE-599 documents6 sources
Severity
6.2MEDIUM
EPSS
0.1%
top 76.06%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 15
Latest updateMay 1

Description

The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file.

CVSS vector

AV:L/AC:H/C:C/I:C/A:CExploitability: 1.9 | Impact: 10.0

Affected Packages2 packages

Also affects: Enterprise Linux 4.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9vrx-rxrx-2pgp: The init2022-05-01
CVEList
CVE-2007-3103: The init2007-07-15

💥Exploits & PoCs

1
Exploit-DB
X.Org xorg-x11-xfs 1.0.2-3.1 - Local Race Condition2008-02-21

📋Vendor Advisories

1
Red Hat
security flaw2007-07-11

💬Community

4
Bugzilla
CVE-2007-3103 security flaw2018-08-16
Bugzilla
CVE-2007-3103 init.d xfs script chown race condition vulnerability2009-03-27
Bugzilla
CVE-2007-3103 init.d xfs script chown race condition vulnerability2007-06-06
Bugzilla
CVE-2007-3103 init.d xfs script chown race condition vulnerability2007-06-06
CVE-2007-3103 (MEDIUM CVSS 6.2) | The init.d script for the X.Org X11 | cvebase.io