bugs.gentoo.orgConfirmation
http://bugs.gentoo.org/show_bug.cgi?id=185660 CVE-2007-3103
X.Org xorg-x11-xfs 1.0.2-3.1 - Local Race Condition
Record summary
CVE-2007-3103 has a selected CVSS score of 6.2; EIP currently links 1 catalogued exploit.
Description
The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBX.Org xorg-x11-xfs 1.0.2-3.1 - Local Race ConditionExploitDB exploitby vl4dZNot analyzed1 file
References
Showing 12 of 23bugzilla.redhat.comConfirmation
http://bugzilla.redhat.com/242903 20070712 Red Hat Enterprise Linux init.d XFS Script chown Race Condition VulnerabilityThird-party advisory
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=557 40945vdb entry
http://osvdb.org/40945 26056Third-party advisory
http://secunia.com/advisories/26056 26081Third-party advisory
http://secunia.com/advisories/26081 26282Third-party advisory
http://secunia.com/advisories/26282 27240Third-party advisory
http://secunia.com/advisories/27240 35674Third-party advisory
http://secunia.com/advisories/35674 GLSA-200710-11Vendor advisory
http://security.gentoo.org/glsa/glsa-200710-11.xml DSA-1342Vendor advisory
http://www.debian.org/security/2007/dsa-1342 RHSA-2007:0519Vendor advisory
http://www.redhat.com/support/errata/RHSA-2007-0519.html