3.7
CVSSv2

CVE-2009-4411

Published: 24/12/2009 Updated: 17/08/2017
CVSS v2 Base Score: 3.7 | Impact Score: 6.4 | Exploitability Score: 1.9
VMScore: 329
Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

The (1) setfacl and (2) getfacl commands in XFS acl 2.2.47, when running in recursive (-R) mode, follow symbolic links even when the --physical (aka -P) or -L option is specified, which might allow local users to modify the ACL for arbitrary files or directories via a symlink attack.

Vulnerable Product Search on Vulmon Subscribe to Product

xfs acl 2.2.47

Vendor Advisories

Debian Bug report logs - #499076 CVE-2009-4411: Physical walk no longer ignores all symlinks Package: acl; Maintainer for acl is Guillem Jover <guillem@debianorg>; Source for acl is src:acl (PTS, buildd, popcon) Reported by: Kevin Shanahan <kmshanah@ucwborgau> Date: Tue, 16 Sep 2008 00:54:02 UTC Severity: serious ...