X Font Server Temporary File Race Conditions Lets Local Users Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1018375
|
|
SecurityTracker URL: http://securitytracker.com/id?1018375
|
|
CVE Reference: CVE-2007-3103
(Links to External Site)
|
Date: Jul 12 2007
|
Impact: Root access via local system
|
Description: A vulnerability was reported in the X Font Server. A local user can obtain elevated privileges on the target system.
The init.d X Font Server script does not properly modify the permissions of a temporary file. A local user can exploit this to change the permissions of arbitrary files to world writable.
iDefense reported this vulnerability.
|
Impact: A local user can obtain root privileges on the target system.
|
Solution: No solution was available at the time of this entry.
|
Vendor URL: www.x.org/ (Links to External Site)
|
Cause: Access control error, State error
|
Underlying OS: Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Thu, 12 Jul 2007 11:09:11 -0400
Subject: X
|
Red Hat said:
A temporary file flaw was found in the way the X.Org X11 xfs font server
startup script executes. A local user could modify the permissions of a
file of their choosing, possibly elevating their local privileges.
(CVE-2007-3103)
|
|