The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file.
CPE | Name | Operator | Version |
---|---|---|---|
fedora_core | eq | 6.0 | |
enterprise_linux | eq | 4.0 es | |
enterprise_linux | eq | 4.0 ws | |
enterprise_linux | eq | 4.0 as | |
enterprise_linux_desktop | eq | 4.0 |
bugs.gentoo.org/show_bug.cgi?id=185660
bugzilla.redhat.com/242903
labs.idefense.com/intelligence/vulnerabilities/display.php?id=557
osvdb.org/40945
secunia.com/advisories/26056
secunia.com/advisories/26081
secunia.com/advisories/26282
secunia.com/advisories/27240
secunia.com/advisories/35674
security.gentoo.org/glsa/glsa-200710-11.xml
www.debian.org/security/2007/dsa-1342
www.redhat.com/support/errata/RHSA-2007-0519.html
www.redhat.com/support/errata/RHSA-2007-0520.html
www.securityfocus.com/archive/1/473869/100/0/threaded
www.securityfocus.com/bid/24888
www.securitytracker.com/id?1018375
exchange.xforce.ibmcloud.com/vulnerabilities/35375
issues.rpath.com/browse/RPL-1485
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10802
www.exploit-db.com/exploits/5167
www.redhat.com/archives/fedora-package-announce/2009-July/msg00095.html
www.redhat.com/archives/fedora-package-announce/2009-July/msg00096.html