USN-516-1: xfsdump vulnerability
20 September 2007
xfsdump vulnerability
Releases
Packages
- xfsdump -
Details
Paul Martin discovered that xfs_fsr creates a temporary directory
with insecure permissions. This allows a local attacker to exploit a
race condition in xfs_fsr to read or overwrite arbitrary files on xfs
filesystems.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 7.04
Ubuntu 6.10
Ubuntu 6.06
In general, a standard system upgrade is sufficient to effect the
necessary changes.