Vulnerability CVE-2007-3103


Published: 2007-07-15   Modified: 2012-02-12

Description:
The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file.

Type:

CWE-59

(Improper Link Resolution Before File Access ('Link Following'))

Vendor: Fedoraproject
Product: Fedora core 
Version: 6.0;
Vendor: Redhat
Product: Enterprise linux desktop 
Version: 4.0;
Product: Enterprise linux 
Version: 4.0;
Product: Linux 

CVSS2 => (AV:L/AC:H/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.2/10
10/10
1.9/10
Exploit range
Attack complexity
Authentication
Local
High
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
http://bugs.gentoo.org/show_bug.cgi?id=185660
http://bugzilla.redhat.com/242903
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=557
http://security.gentoo.org/glsa/glsa-200710-11.xml
http://www.debian.org/security/2007/dsa-1342
http://www.redhat.com/support/errata/RHSA-2007-0519.html
http://www.redhat.com/support/errata/RHSA-2007-0520.html
http://www.securityfocus.com/archive/1/473869/100/0/threaded
http://www.securityfocus.com/bid/24888
http://www.securitytracker.com/id?1018375
https://exchange.xforce.ibmcloud.com/vulnerabilities/35375
https://issues.rpath.com/browse/RPL-1485
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10802
https://www.exploit-db.com/exploits/5167
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00095.html
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00096.html

Related CVE
CVE-2019-14835
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descript...
CVE-2019-14813
A flaw was found in ghostscript, versions 9.x before 9.28, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable se...
CVE-2019-6648
On version 1.9.0, If DEBUG logging is enable, F5 Container Ingress Service (CIS) for Kubernetes and Red Hat OpenShift (k8s-bigip-ctlr) log files may contain BIG-IP secrets such as SSL Private Keys and Private key Passphrases as provided as inputs by ...
CVE-2019-1125
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1071, CVE-2019-1073.
CVE-2019-10140
A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a denial of service situation via NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c....
CVE-2019-10201
It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the <Signature> sections, the message is still accepted, and the message can be modified....
CVE-2019-10199
It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain.
CVE-2019-10176
A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this t...

Copyright 2019, cxsecurity.com

 

Back to Top